Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A financial institution is designing a new customer-facing web application that will handle sensitive transaction data. The application will be hosted on Azure App Service. The security architect needs to implement a solution to protect the application from common web vulnerabilities such as SQL injection and cross-site scripting (XSS) at the network edge. The solution must also provide centralized management and logging. Which Azure service should the architect recommend?

  1. AAzure Front Door with Web Application Firewall (WAF)
  2. BAzure Network Security Groups (NSGs)
  3. CAzure DDoS Protection Standard
  4. DAzure Firewall Premium
Show answer & explanation

Correct answer: A. Azure Front Door with Web Application Firewall (WAF)

Azure Front Door with WAF provides protection against common web vulnerabilities like SQL injection and XSS at the edge, before traffic reaches the backend application. It also offers centralized management and logging for WAF policies, making it suitable for customer-facing web applications.

Why the other options are wrong

  • B. Azure Network Security Groups (NSGs) filter network traffic at the network interface or subnet level based on IP addresses and ports, not application-layer attacks.
  • C. Azure DDoS Protection Standard protects against volumetric and protocol attacks, not application-level vulnerabilities like SQL injection or XSS.
  • D. Azure Firewall Premium is a stateful firewall for network traffic, not an application-layer firewall (WAF) designed to protect against specific web vulnerabilities.

Azure Front Door WAF

A Web Application Firewall (WAF) integrated with Azure Front Door that protects web applications from common web vulnerabilities and exploits at the network edge.

  • Operates at Layer 7 (application layer)
  • Protects against OWASP Top 10 vulnerabilities
  • Centralized management and logging
  • Global threat intelligence

Memory trick: Front Door WAF guards the web's entrance.

More Design security for applications and data questions