Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium
An organization is deploying a new web application and requires robust protection against common web-based attacks such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). They also need to ensure high availability and load balancing for the application servers. Which security device is specifically designed to address these requirements effectively?
- ASecure Web Gateway (SWG)
- BIntrusion Prevention System (IPS)
- CWeb Application Firewall (WAF)
- DNext-Generation Firewall (NGFW)
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specifically designed to protect web applications from common attacks like SQL injection, XSS, and CSRF by inspecting HTTP/HTTPS traffic. Many WAFs also incorporate load balancing and high availability features.
Why the other options are wrong
- A. SWGs protect internal users from external web threats, not external users from internal web application vulnerabilities.
- B. IPS detects and prevents various network-based attacks but lacks the deep application-layer understanding of a WAF for web applications.
- D. NGFWs provide broader network security but are not as specialized in application-layer attacks (like SQL injection) as a WAF.
Web Application Firewall (WAF)
A security solution that monitors, filters, and blocks HTTP/HTTPS traffic to and from a web application. It protects web applications from common attacks by enforcing a set of rules against malicious traffic.
- Operates at the application layer (Layer 7).
- Protects against OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF).
- Can be network-based, host-based, or cloud-based.
- Often includes load balancing and SSL offloading features.
Memory trick: To guard the web app, you need a specific type of wall.