Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium

An organization is deploying a new web application and requires robust protection against common web-based attacks such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). They also need to ensure high availability and load balancing for the application servers. Which security device is specifically designed to address these requirements effectively?

  1. ASecure Web Gateway (SWG)
  2. BIntrusion Prevention System (IPS)
  3. CWeb Application Firewall (WAF)
  4. DNext-Generation Firewall (NGFW)
Show answer & explanation

Correct answer: C. Web Application Firewall (WAF)

A Web Application Firewall (WAF) is specifically designed to protect web applications from common attacks like SQL injection, XSS, and CSRF by inspecting HTTP/HTTPS traffic. Many WAFs also incorporate load balancing and high availability features.

Why the other options are wrong

  • A. SWGs protect internal users from external web threats, not external users from internal web application vulnerabilities.
  • B. IPS detects and prevents various network-based attacks but lacks the deep application-layer understanding of a WAF for web applications.
  • D. NGFWs provide broader network security but are not as specialized in application-layer attacks (like SQL injection) as a WAF.

Web Application Firewall (WAF)

A security solution that monitors, filters, and blocks HTTP/HTTPS traffic to and from a web application. It protects web applications from common attacks by enforcing a set of rules against malicious traffic.

  • Operates at the application layer (Layer 7).
  • Protects against OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF).
  • Can be network-based, host-based, or cloud-based.
  • Often includes load balancing and SSL offloading features.

Memory trick: To guard the web app, you need a specific type of wall.

More Visibility and Enforcement questions