Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityEasy

A large e-commerce company is experiencing frequent web-based attacks, including SQL injection and cross-site scripting, targeting their cloud-hosted application. They need a security solution that can detect and prevent these specific application-layer attacks before they reach the backend servers, without requiring modifications to the application code. Which cloud security technology is best suited for this task?

  1. ACloud Security Posture Management (CSPM)
  2. BNetwork Access Control List (NACL)
  3. CWeb Application Firewall (WAF)
  4. DVirtual Private Network (VPN) Gateway
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and cross-site scripting by filtering and monitoring HTTP traffic, operating at the application layer (Layer 7).

Why the other options are wrong

  • A. CSPM focuses on identifying and remediating cloud infrastructure misconfigurations, not active web application attack prevention.
  • B. NACLs operate at the subnet level (Layer 3/4) and cannot detect application-layer attacks like SQL injection.
  • D. VPN gateways provide secure network connectivity, not protection against web application attacks.

Web Application Firewall (WAF)

A security solution that protects web applications from common web-based attacks by filtering and monitoring HTTP traffic between the application and the internet.

  • Operates at the application layer (Layer 7).
  • Protects against OWASP Top 10 vulnerabilities (e.g., SQLi, XSS).
  • Can be deployed as a cloud service, appliance, or software.

Memory trick: A WAF is like a bouncer for your website, checking everyone at the door for bad intentions.

More Cloud Security questions