Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A financial services organization is building a new customer-facing web application on Azure App Service. The application will frequently access customer financial data stored in an Azure SQL Database. The security architect needs to implement a comprehensive strategy to protect the application from common web vulnerabilities, specifically SQL injection and cross-site scripting (XSS), and ensure consistent security policies are applied across all application instances. Which Azure service should be deployed in front of the App Service to meet these requirements?
- AAzure Traffic Manager with DNS-based load balancing.
- BAzure Firewall with Network Security Groups (NSGs).
- CAzure Application Gateway with Web Application Firewall (WAF) enabled.
- DAzure Front Door with Azure DDoS Protection.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Application Gateway with Web Application Firewall (WAF) enabled.
Azure Application Gateway with Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS by inspecting HTTP/HTTPS traffic.
Why the other options are wrong
- A. Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic across services globally; it does not provide any security features like WAF.
- B. Azure Firewall is a network-level firewall (Layer 3/4) that protects against network threats but does not inspect HTTP/HTTPS traffic for web application-specific attacks like SQL injection or XSS.
- D. Azure Front Door provides global load balancing and DDoS protection but its WAF capabilities are more focused on edge protection; Application Gateway WAF is more comprehensive for web application attacks.
Azure Application Gateway WAF
A feature of Azure Application Gateway that provides centralized protection of your web applications from common exploits and vulnerabilities (e.g., OWASP Top 10) by inspecting HTTP/HTTPS traffic.
- Protects against SQL injection, XSS, and other web attacks.
- Operates at Layer 7 (application layer).
- Can be deployed in front of web applications hosted in Azure or on-premises.
Memory trick: App Gateway WAF for Web App Defense.