Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
A cybersecurity team is performing a penetration test against a cloud-native application. During their reconnaissance phase, they discover that one of the application's API endpoints is vulnerable to SQL injection and cross-site scripting (XSS) attacks. To mitigate these specific threats at the edge of the network before they reach the application, which cloud security technology should the team recommend?
- ACloud Security Posture Management (CSPM)
- BCloud Workload Protection Platform (CWPP)
- CWeb Application Firewall (WAF)
- DNetwork Access Control List (NACL)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS by filtering HTTP/S traffic at the application layer (Layer 7) before it reaches the application server, making it ideal for mitigating these threats at the network edge.
Why the other options are wrong
- A. CSPM monitors configuration and compliance, not real-time application-layer attack detection and blocking.
- B. CWPPs protect workloads (VMs, containers) at a deeper level, but a WAF is the primary 'edge' defense for web application-specific attacks.
- D. NACLs operate at the network layer (Layer 4) and cannot detect application-layer attacks like SQL injection or XSS.
Web Application Firewall (WAF)
A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against common web-based attacks like SQL injection and XSS.
- Operates at the application layer (Layer 7)
- Protects against specific web exploits
- Deployed at the edge of the network
Memory trick: WAF is your web app's personal bodyguard.