Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy
A large e-commerce company is experiencing frequent web-based attacks, including SQL injection and cross-site scripting, targeting their cloud-hosted application. They need a security solution that can detect and prevent these specific application-layer attacks before they reach the backend servers, without requiring modifications to the application code. Which cloud security technology is best suited for this task?
- ACloud Security Posture Management (CSPM)
- BNetwork Access Control List (NACL)
- CWeb Application Firewall (WAF)
- DVirtual Private Network (VPN) Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and cross-site scripting by filtering and monitoring HTTP traffic, operating at the application layer (Layer 7).
Why the other options are wrong
- A. CSPM focuses on identifying and remediating cloud infrastructure misconfigurations, not active web application attack prevention.
- B. NACLs operate at the subnet level (Layer 3/4) and cannot detect application-layer attacks like SQL injection.
- D. VPN gateways provide secure network connectivity, not protection against web application attacks.
Web Application Firewall (WAF)
A security solution that protects web applications from common web-based attacks by filtering and monitoring HTTP traffic between the application and the internet.
- Operates at the application layer (Layer 7).
- Protects against OWASP Top 10 vulnerabilities (e.g., SQLi, XSS).
- Can be deployed as a cloud service, appliance, or software.
Memory trick: A WAF is like a bouncer for your website, checking everyone at the door for bad intentions.