Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A financial services organization is building a new customer-facing web application on Azure. The application will be exposed to the public internet and must be protected against common web vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). Additionally, the solution needs to provide SSL/TLS termination, centralized certificate management, and load balancing for the backend web servers. Which Azure service should the security architect deploy to meet these requirements?

  1. AAzure Front Door
  2. BAzure DDoS Protection
  3. CAzure Load Balancer
  4. DAzure Application Gateway with WAF
Show answer & explanation

Correct answer: D. Azure Application Gateway with WAF

Azure Application Gateway with its Web Application Firewall (WAF) capability is specifically designed to protect web applications from common web vulnerabilities (OWASP Top 10) and provides SSL/TLS termination, centralized certificate management, and application-layer load balancing.

Why the other options are wrong

  • A. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. While it offers WAF, Application Gateway is typically used for regional deployments and provides more granular control over backend pools within a VNet.
  • B. Azure DDoS Protection protects against volumetric and protocol attacks but does not address application-layer vulnerabilities like SQL injection or XSS.
  • C. Azure Load Balancer operates at Layer 4 (TCP/UDP) and provides basic network load balancing, but it does not offer WAF capabilities or SSL/TLS termination at the application layer.

Azure Application Gateway WAF

Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. Its Web Application Firewall (WAF) capability provides centralized protection of your web applications from common exploits and vulnerabilities.

  • Protects against OWASP Top 10 vulnerabilities.
  • Provides SSL/TLS termination and end-to-end encryption.
  • Offers application-layer load balancing.
  • Integrates with Azure Monitor for detailed logging.

Memory trick: App Gateway with WAF is the bouncer and traffic cop for your web apps.

More Design security for applications and data questions