Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
A cloud security architect is designing a highly secure environment for a financial services application. They need to ensure that the application's network traffic is inspected and filtered at the application layer (Layer 7) for malicious content, such as SQL injection attempts or cross-site scripting (XSS). Which security technology is best suited for this specific task?
- AStateful Firewall
- BWeb Application Firewall (WAF)
- CNetwork Access Control List (NACL)
- DSecurity Group
Show answer & explanationAnswer & explanation
Correct answer: B. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks by filtering and monitoring HTTP traffic at Layer 7, detecting and blocking threats like SQL injection and XSS.
Why the other options are wrong
- A. A stateful firewall typically operates at Layer 3/4, tracking connection states but not inspecting application-layer payloads for specific web attack patterns.
- C. NACLs are stateless, operating at the network layer (Layer 3/4), filtering traffic based on IP addresses and ports.
- D. Security groups are stateful virtual firewalls for instances, operating at Layer 3/4, similar to a basic firewall, not a WAF.
Web Application Firewall (WAF)
A security solution that protects web applications from common web exploits by filtering and monitoring HTTP traffic between a web application and the internet, primarily operating at the application layer (Layer 7).
- Defends against SQL injection, XSS, broken authentication.
- Inspects HTTP/HTTPS requests and responses.
- Can be network-based, host-based, or cloud-based service.
Memory trick: WAF is like a 'bouncer' for your web app, checking every visitor for bad intentions.