Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A web development team has deployed a new e-commerce application. A security audit reveals that the application is vulnerable to SQL injection attacks due to improper input validation. Which security device or service is specifically designed to protect web applications from such vulnerabilities without requiring changes to the application code?
- AWeb Application Firewall (WAF)
- BNext-Generation Firewall (NGFW)
- CStateful Firewall
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: A. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities by inspecting and filtering HTTP/HTTPS traffic.
Why the other options are wrong
- B. While an NGFW offers advanced features, its primary focus is broader network security, not specific application-layer attacks like SQL injection without deep, specialized web application inspection.
- C. A stateful firewall primarily operates at network and transport layers, inspecting connection states, and cannot detect application-specific attacks like SQL injection.
- D. An IPS detects and prevents known threats based on signatures or behavioral analysis, but a WAF is specialized for the unique vulnerabilities of web applications.
Web Application Firewall (WAF)
A Web Application Firewall (WAF) is a security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting it from common web-based attacks like SQL injection and XSS.
- Operates at OSI Layer 7 (Application Layer).
- Protects against OWASP Top 10 vulnerabilities.
- Can be deployed as a network appliance, host-based plugin, or cloud service.
Memory trick: WAF: 'W'eb apps get 'A'll the 'F'iltering.