Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A global financial institution is designing its cloud architecture in Azure. They require a solution to protect their web applications and APIs from common web exploits and bots, enforce granular access controls based on source IP and geo-location, and provide centralized management across multiple regions. They also need to integrate with Azure Sentinel for security information and event management (SIEM). Which Azure service should be recommended?

  1. AAzure Application Gateway with WAF
  2. BAzure Firewall Premium
  3. CAzure Front Door with WAF
  4. DAzure DDoS Protection Standard
Show answer & explanation

Correct answer: C. Azure Front Door with WAF

Azure Front Door with its integrated Web Application Firewall (WAF) is a global, highly scalable service that provides protection against common web exploits, bot protection, and granular access controls (including geo-filtering) at the edge. Its global nature and integration with Azure Sentinel make it ideal for a multinational institution's web applications and APIs across multiple regions.

Why the other options are wrong

  • A. Azure Application Gateway with WAF is a regional service. While it provides WAF capabilities, it wouldn't offer global load balancing, geo-filtering, or centralized management across multiple regions as effectively as Front Door.
  • B. Azure Firewall Premium is a network firewall that provides advanced threat protection at the network layer for virtual networks. It's not specifically designed for web application protection (Layer 7) or global web traffic management.
  • D. Azure DDoS Protection Standard protects against distributed denial-of-service attacks at the network layer. While important, it does not provide web application firewall capabilities, bot protection, or granular access controls based on IP/geo-location.

Azure Front Door with WAF

A global, scalable, and secure entry point for web applications and APIs that provides application acceleration, global load balancing, and WAF capabilities to protect against common web exploits and manage traffic.

  • Global service, operates at the edge.
  • Integrated Web Application Firewall (WAF).
  • Protects against common web exploits and bots.
  • Supports geo-filtering and IP-based access control.
  • Centralized management for multi-region deployments.

Memory trick: Front Door guards your global web apps at the very edge.

More Design security for infrastructure questions