ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium

A large e-commerce company is experiencing frequent distributed denial-of-service (DDoS) attacks targeting its web servers. These attacks often involve a flood of legitimate-looking HTTP requests, making them difficult to distinguish from normal user traffic. The security team needs a solution that can identify and mitigate these sophisticated application-layer attacks without blocking legitimate users. Which of the following security devices is BEST suited for this purpose?

  1. AStateful Firewall
  2. BWeb Application Firewall (WAF)
  3. CNetwork Intrusion Detection System (NIDS)
  4. DIntrusion Prevention System (IPS)
Show answer & explanation

Correct answer: B. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from various attacks, including application-layer DDoS. It operates at Layer 7 of the OSI model, allowing it to inspect HTTP/HTTPS traffic, analyze request patterns, and distinguish malicious requests from legitimate ones based on application logic, not just network parameters.

Why the other options are wrong

  • A. A stateful firewall operates at lower layers and struggles to analyze application-layer content or sophisticated HTTP flood attacks.
  • C. A NIDS detects intrusions but primarily provides alerts; it does not actively block or mitigate attacks in the same way an IPS or WAF does.
  • D. An IPS can detect and prevent some DDoS, but a WAF is specialized for HTTP/HTTPS application-layer attacks, offering deeper inspection.

Web Application Firewall (WAF)

A security solution that protects web applications from common web-based attacks by filtering, monitoring, and blocking malicious HTTP traffic to and from a web application. It operates at Layer 7 of the OSI model.

  • Protects against application-layer attacks (e.g., SQL injection, XSS, application DDoS).
  • Inspects HTTP/HTTPS traffic content.
  • Can be network-based, host-based, or cloud-based.
  • Provides granular control over web traffic.

Memory trick: WAFs Guard Web Apps Fiercely.

More Communication and Network Security questions