Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityEasy
A development team is deploying a new web application to a public cloud environment. They want to protect the application from common web-based attacks such as SQL injection, cross-site scripting (XSS), and DDoS attacks targeting the application layer. Which cloud security technology is specifically designed to address these threats?
- ACloud Access Security Broker (CASB)
- BVirtual Private Cloud (VPC)
- CWeb Application Firewall (WAF)
- DNetwork Access Control List (NACL)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web exploits and vulnerabilities, including SQL injection, XSS, and application-layer DDoS attacks, by filtering and monitoring HTTP traffic.
Why the other options are wrong
- A. CASBs focus on securing cloud access, data governance, and compliance for various cloud services, not primarily web application exploits.
- B. VPCs provide an isolated network environment in the cloud but do not inherently protect against application-layer attacks.
- D. NACLs operate at the subnet level, controlling traffic based on IP addresses and ports, not application-layer attacks.
Web Application Firewall (WAF)
A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting it from various web-based attacks.
- Protects against OWASP Top 10 vulnerabilities
- Operates at Layer 7 (Application Layer)
- Can be hardware, software, or cloud-based
Memory trick: WAF Guards the Web's Front Door.