Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityEasy

A development team is deploying a new web application to a public cloud environment. They want to protect the application from common web-based attacks such as SQL injection, cross-site scripting (XSS), and DDoS attacks targeting the application layer. Which cloud security technology is specifically designed to address these threats?

  1. ACloud Access Security Broker (CASB)
  2. BVirtual Private Cloud (VPC)
  3. CWeb Application Firewall (WAF)
  4. DNetwork Access Control List (NACL)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common web exploits and vulnerabilities, including SQL injection, XSS, and application-layer DDoS attacks, by filtering and monitoring HTTP traffic.

Why the other options are wrong

  • A. CASBs focus on securing cloud access, data governance, and compliance for various cloud services, not primarily web application exploits.
  • B. VPCs provide an isolated network environment in the cloud but do not inherently protect against application-layer attacks.
  • D. NACLs operate at the subnet level, controlling traffic based on IP addresses and ports, not application-layer attacks.

Web Application Firewall (WAF)

A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting it from various web-based attacks.

  • Protects against OWASP Top 10 vulnerabilities
  • Operates at Layer 7 (Application Layer)
  • Can be hardware, software, or cloud-based

Memory trick: WAF Guards the Web's Front Door.

More Cloud Security questions