Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A network security engineer is deploying a new web application and needs to ensure that only legitimate HTTP/HTTPS traffic reaches the web servers, while blocking common web-based attacks like SQL injection and cross-site scripting (XSS). Which network security device is specifically designed to provide this type of advanced, application-layer protection?
- AIntrusion Prevention System (IPS)
- BLoad Balancer
- CWeb Application Firewall (WAF)
- DNext-Generation Firewall (NGFW)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks such as SQL injection, XSS, and other OWASP Top 10 threats. While NGFWs and IPS can offer some application-level awareness, a WAF provides specialized, deep inspection of HTTP/HTTPS traffic.
Why the other options are wrong
- A. IPS devices detect and prevent known threats based on signatures and behavioral analysis, but a WAF is more focused on the nuances of web application vulnerabilities.
- B. A Load Balancer distributes traffic across multiple servers and provides some basic security, but not advanced web application attack prevention.
- D. NGFWs offer broader network security but are not as specialized in web application attack detection as a WAF.
Web Application Firewall (WAF)
A security solution that monitors, filters, and blocks HTTP/HTTPS traffic to and from a web application.
- Protects against OWASP Top 10 threats
- Operates at the application layer (Layer 7)
- Inspects web requests and responses
Memory trick: WAF guards the web's front door.