Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium
A company requires a network solution to filter incoming internet traffic to its Azure Virtual Network, protecting web applications from common web vulnerabilities like SQL injection and cross-site scripting. The solution must also provide centralized management and logging. Which Azure networking service should be recommended?
- AAzure Firewall
- BAzure Front Door
- CAzure Application Gateway with WAF
- DAzure Network Security Groups (NSGs)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Application Gateway with WAF
Azure Application Gateway with its Web Application Firewall (WAF) capability is specifically designed to protect web applications from common web-based attacks (like SQL injection and XSS). It operates at Layer 7 and provides centralized management and logging for application-level traffic.
Why the other options are wrong
- A. Azure Firewall is a stateful firewall operating at Layer 3/4, providing network-level protection, but not application-level WAF capabilities.
- B. Azure Front Door provides global load balancing and WAF, but Application Gateway is the correct choice for regional WAF protection in front of web applications within a VNet.
- D. NSGs operate at Layer 4 (transport) and Layer 3 (network), providing basic packet filtering, but cannot protect against web vulnerabilities like SQL injection.
Azure WAF
Web Application Firewall (WAF) in Azure protects web applications from common web-based attacks like SQL injection and cross-site scripting (XSS).
- Operates at Layer 7 (application layer).
- Available with Application Gateway and Front Door.
- Protects against OWASP Top 10 vulnerabilities.
- Provides centralized management and logging.
Memory trick: Application Gateway with WAF is the 'guardian' of your 'web apps' from 'bad traffic'.