EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A web administrator is configuring a new web server and is advised to implement a Web Application Firewall (WAF) as part of the security architecture. What is the primary function of a WAF?

  1. ATo manage user identities and access privileges for the application.
  2. BTo perform vulnerability scanning on the web application code.
  3. CTo encrypt all traffic between the client and the server.
  4. DTo filter, monitor, and block HTTP traffic to and from a web application.
Show answer & explanation

Correct answer: D. To filter, monitor, and block HTTP traffic to and from a web application.

A Web Application Firewall (WAF) is specifically designed to protect web applications by filtering, monitoring, and blocking malicious HTTP traffic. It operates at Layer 7 of the OSI model, inspecting web application traffic for common attacks like SQL injection and XSS.

Why the other options are wrong

  • A. User identity and access management (IAM) is handled by separate systems, not a WAF.
  • B. Vulnerability scanning is a separate process that identifies flaws, a WAF protects against exploitation of those flaws.
  • C. Encryption is primarily handled by SSL/TLS, not a WAF's primary function.

Web Application Firewall (WAF)

A security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against web-based attacks.

  • Operates at Layer 7 (Application Layer) of the OSI model.
  • Protects against common vulnerabilities like SQL Injection, XSS, and CSRF.
  • Can be network-based, host-based, or cloud-based.

Memory trick: WAF is the 'Watchman Against Frauds' for web apps.

More Web Application Hacking questions