Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A security engineer is configuring a web application firewall (WAF) to protect an online e-commerce platform. The WAF needs to detect and block SQL injection attempts, cross-site scripting (XSS) attacks, and other common web-based vulnerabilities. Which layer of the OSI model does a WAF primarily operate at to perform these functions?
- ALayer 2 (Data Link)
- BLayer 7 (Application)
- CLayer 3 (Network)
- DLayer 4 (Transport)
Show answer & explanationAnswer & explanation
Correct answer: B. Layer 7 (Application)
A Web Application Firewall (WAF) primarily operates at Layer 7 (Application Layer) of the OSI model. It inspects and filters HTTP/HTTPS traffic, which is an application-layer protocol, to detect and block attacks like SQL injection and XSS that target vulnerabilities in web applications themselves. Lower layers do not have visibility into the application-specific content and syntax necessary for these detections.
Why the other options are wrong
- A. Layer 2 (Data Link) deals with MAC addresses and frame forwarding, too low for application-level attack detection.
- C. Layer 3 (Network) deals with IP addresses and routing, not sufficient for inspecting web application content.
- D. Layer 4 (Transport) deals with TCP/UDP ports and segments, but not the actual HTTP/HTTPS content or application logic.
WAF OSI Layer
A Web Application Firewall (WAF) primarily operates at Layer 7 (Application Layer) of the OSI model, inspecting and filtering HTTP/HTTPS traffic to protect web applications from specific attacks.
- Inspects HTTP/HTTPS traffic.
- Protects against SQL injection, XSS, etc.
- Understands application-specific syntax and logic.
Memory trick: Each layer has its own guard, but the WAF guards the 'application door'.