EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
A security team is implementing a defense-in-depth strategy for a critical web application. They have decided to place a reverse proxy in front of the web server. This reverse proxy will be configured to inspect incoming HTTP requests for malicious patterns, filter out known attack signatures, and block suspicious IP addresses before requests even reach the backend application. Which type of web application security component is this reverse proxy primarily acting as?
- AContent Delivery Network (CDN)
- BIntrusion Detection System (IDS)
- CLoad Balancer
- DWeb Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: D. Web Application Firewall (WAF)
The description of the reverse proxy inspecting requests for malicious patterns, filtering attack signatures, and blocking suspicious IPs before they reach the application precisely matches the function of a Web Application Firewall (WAF).
Why the other options are wrong
- A. A CDN caches content closer to users for faster delivery and can offer some DDoS protection, but not granular web application attack filtering.
- B. An IDS monitors traffic for suspicious activity and alerts, but typically doesn't actively block or filter requests like a WAF.
- C. A Load Balancer distributes traffic across multiple servers, primarily for performance and availability, not deep security inspection.
Web Application Firewall (WAF)
A Web Application Firewall (WAF) is a security solution that protects web applications from various attacks by filtering, monitoring, and blocking malicious HTTP traffic.
- Operates at Layer 7 (Application Layer) of the OSI model.
- Protects against common web vulnerabilities like SQL Injection, XSS, and CSRF.
- Can be network-based, host-based, or cloud-based.
Memory trick: Defend Web Apps with Layers.