Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium

An organization is deploying several web applications in Azure and wants to protect them from common web-based attacks such as SQL injection and cross-site scripting. They also need to ensure that traffic is load-balanced across their backend web servers. Which Azure service combines these functionalities?

  1. AAzure DDoS Protection Standard
  2. BAzure Firewall
  3. CAzure Network Security Group (NSG)
  4. DAzure Application Gateway with WAF
Show answer & explanation

Correct answer: D. Azure Application Gateway with WAF

Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. It includes a Web Application Firewall (WAF) that provides centralized protection of your web applications from common exploits and vulnerabilities like SQL injection and cross-site scripting.

Why the other options are wrong

  • A. Azure DDoS Protection Standard protects against distributed denial of service attacks, not application-layer exploits.
  • B. Azure Firewall provides network-level threat protection for all resources, not specifically web application attacks.
  • C. Azure NSG filters network traffic at the VM level based on IP addresses and ports, not web application layer attacks.

Azure Application Gateway WAF

A web application firewall (WAF) capability integrated into Azure Application Gateway, providing centralized protection for web applications.

  • Protects against common web vulnerabilities (e.g., SQL injection, XSS).
  • Operates at Layer 7 (HTTP/HTTPS).
  • Combines WAF functionality with application-level load balancing.

Memory trick: App Gateway WAF stands guard at your web's front door.

More Describe Azure identity, security, and networking questions