Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy

A financial services organization is building a new customer-facing web application on Azure App Service. The application will frequently access customer financial data stored in an Azure SQL Database. The security architect needs to implement a comprehensive strategy to protect the application from common web vulnerabilities, specifically SQL injection and cross-site scripting (XSS), and ensure consistent security policies are applied across all application instances. Which Azure service should be deployed in front of the App Service to meet these requirements?

  1. AAzure Traffic Manager with DNS-based load balancing.
  2. BAzure Firewall with Network Security Groups (NSGs).
  3. CAzure Application Gateway with Web Application Firewall (WAF) enabled.
  4. DAzure Front Door with Azure DDoS Protection.
Show answer & explanation

Correct answer: C. Azure Application Gateway with Web Application Firewall (WAF) enabled.

Azure Application Gateway with Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS by inspecting HTTP/HTTPS traffic.

Why the other options are wrong

  • A. Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic across services globally; it does not provide any security features like WAF.
  • B. Azure Firewall is a network-level firewall (Layer 3/4) that protects against network threats but does not inspect HTTP/HTTPS traffic for web application-specific attacks like SQL injection or XSS.
  • D. Azure Front Door provides global load balancing and DDoS protection but its WAF capabilities are more focused on edge protection; Application Gateway WAF is more comprehensive for web application attacks.

Azure Application Gateway WAF

A feature of Azure Application Gateway that provides centralized protection of your web applications from common exploits and vulnerabilities (e.g., OWASP Top 10) by inspecting HTTP/HTTPS traffic.

  • Protects against SQL injection, XSS, and other web attacks.
  • Operates at Layer 7 (application layer).
  • Can be deployed in front of web applications hosted in Azure or on-premises.

Memory trick: App Gateway WAF for Web App Defense.

More Design security for applications and data questions