Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingMedium
An organization is deploying several web applications in Azure and wants to protect them from common web-based attacks such as SQL injection and cross-site scripting. They also need to ensure that traffic is load-balanced across their backend web servers. Which Azure service combines these functionalities?
- AAzure DDoS Protection Standard
- BAzure Firewall
- CAzure Network Security Group (NSG)
- DAzure Application Gateway with WAF
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Application Gateway with WAF
Azure Application Gateway is a web traffic load balancer that enables you to manage traffic to your web applications. It includes a Web Application Firewall (WAF) that provides centralized protection of your web applications from common exploits and vulnerabilities like SQL injection and cross-site scripting.
Why the other options are wrong
- A. Azure DDoS Protection Standard protects against distributed denial of service attacks, not application-layer exploits.
- B. Azure Firewall provides network-level threat protection for all resources, not specifically web application attacks.
- C. Azure NSG filters network traffic at the VM level based on IP addresses and ports, not web application layer attacks.
Azure Application Gateway WAF
A web application firewall (WAF) capability integrated into Azure Application Gateway, providing centralized protection for web applications.
- Protects against common web vulnerabilities (e.g., SQL injection, XSS).
- Operates at Layer 7 (HTTP/HTTPS).
- Combines WAF functionality with application-level load balancing.
Memory trick: App Gateway WAF stands guard at your web's front door.