Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy

A network security engineer is deploying a new web application and needs to ensure that only legitimate HTTP/HTTPS traffic reaches the web servers, while blocking common web-based attacks like SQL injection and cross-site scripting (XSS). Which network security device is specifically designed to provide this type of advanced, application-layer protection?

  1. AIntrusion Prevention System (IPS)
  2. BLoad Balancer
  3. CWeb Application Firewall (WAF)
  4. DNext-Generation Firewall (NGFW)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks such as SQL injection, XSS, and other OWASP Top 10 threats. While NGFWs and IPS can offer some application-level awareness, a WAF provides specialized, deep inspection of HTTP/HTTPS traffic.

Why the other options are wrong

  • A. IPS devices detect and prevent known threats based on signatures and behavioral analysis, but a WAF is more focused on the nuances of web application vulnerabilities.
  • B. A Load Balancer distributes traffic across multiple servers and provides some basic security, but not advanced web application attack prevention.
  • D. NGFWs offer broader network security but are not as specialized in web application attack detection as a WAF.

Web Application Firewall (WAF)

A security solution that monitors, filters, and blocks HTTP/HTTPS traffic to and from a web application.

  • Protects against OWASP Top 10 threats
  • Operates at the application layer (Layer 7)
  • Inspects web requests and responses

Memory trick: WAF guards the web's front door.

More Network Security questions