Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A financial institution is designing a new customer-facing web application that will handle sensitive personal and transaction data. The application will be hosted on Azure App Service. To protect the application from common web-based attacks such as SQL injection, cross-site scripting (XSS), and denial-of-service (DoS) attacks, while also providing load balancing and SSL offloading, which Azure service should be deployed in front of the App Service?
- AAzure Front Door
- BAzure Application Gateway with Web Application Firewall (WAF)
- CAzure Firewall
- DAzure Network Security Group (NSG)
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Application Gateway with Web Application Firewall (WAF)
Azure Application Gateway with Web Application Firewall (WAF) provides layer 7 load balancing, SSL termination, and protection against common web vulnerabilities like SQL injection and XSS, making it ideal for securing web applications hosted on App Service.
Why the other options are wrong
- A. Azure Front Door provides global load balancing and WAF capabilities but is typically used for multi-region applications or global user bases, and Application Gateway is often preferred for regional WAF protection in front of App Service.
- C. Azure Firewall is a network-level firewall (Layer 4/5) and does not provide web application-specific protection against SQL injection or XSS.
- D. Azure Network Security Groups (NSGs) provide basic network traffic filtering (Layer 4) and cannot protect against web application layer attacks.
Azure Application Gateway WAF
A web traffic load balancer that enables you to manage traffic to your web applications. It includes a Web Application Firewall (WAF) that protects web applications from common web vulnerabilities and exploits.
- Layer 7 (application layer) load balancing.
- Web Application Firewall (WAF) for common web attacks.
- SSL/TLS termination (offloading).
- Ideal for securing web applications like those on Azure App Service.
Memory trick: Application Gateway WAF is the bouncer for your web app, checking for bad guests.