Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium

A company requires a network solution to filter incoming internet traffic to its Azure Virtual Network, protecting web applications from common web vulnerabilities like SQL injection and cross-site scripting. The solution must also provide centralized management and logging. Which Azure networking service should be recommended?

  1. AAzure Firewall
  2. BAzure Front Door
  3. CAzure Application Gateway with WAF
  4. DAzure Network Security Groups (NSGs)
Show answer & explanation

Correct answer: C. Azure Application Gateway with WAF

Azure Application Gateway with its Web Application Firewall (WAF) capability is specifically designed to protect web applications from common web-based attacks (like SQL injection and XSS). It operates at Layer 7 and provides centralized management and logging for application-level traffic.

Why the other options are wrong

  • A. Azure Firewall is a stateful firewall operating at Layer 3/4, providing network-level protection, but not application-level WAF capabilities.
  • B. Azure Front Door provides global load balancing and WAF, but Application Gateway is the correct choice for regional WAF protection in front of web applications within a VNet.
  • D. NSGs operate at Layer 4 (transport) and Layer 3 (network), providing basic packet filtering, but cannot protect against web vulnerabilities like SQL injection.

Azure WAF

Web Application Firewall (WAF) in Azure protects web applications from common web-based attacks like SQL injection and cross-site scripting (XSS).

  • Operates at Layer 7 (application layer).
  • Available with Application Gateway and Front Door.
  • Protects against OWASP Top 10 vulnerabilities.
  • Provides centralized management and logging.

Memory trick: Application Gateway with WAF is the 'guardian' of your 'web apps' from 'bad traffic'.

More Design infrastructure solutions questions