Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy
A company is deploying a new web application that uses Azure Front Door as a global load balancer and Web Application Firewall (WAF). To comply with regional data residency laws and prevent access from sanctioned countries, the security team needs to restrict access to the web application based on the geographical location of the client. Which specific WAF feature in Azure Front Door should be configured?
- AGeo-filtering
- BRate limiting
- CCustom rules
- DManaged rules (OWASP Top 10)
Show answer & explanationAnswer & explanation
Correct answer: A. Geo-filtering
Geo-filtering is the specific WAF feature in Azure Front Door that allows you to control access to your web applications based on the client's geographical location. This directly addresses the requirement to restrict access from specific countries or regions.
Why the other options are wrong
- B. Rate limiting controls the number of requests allowed from a client within a time period to prevent DDoS attacks and abuse, but it does not filter by geography.
- C. Custom rules allow defining specific conditions and actions for traffic, but geo-filtering is a specialized type of custom rule or a built-in feature for this specific purpose.
- D. Managed rules (OWASP Top 10) protect against common web vulnerabilities like SQL injection and XSS, but they do not filter traffic based on geographical origin.
Azure Front Door WAF Geo-filtering
Azure Front Door's WAF geo-filtering capability allows you to control access to your web applications based on the client's geographical location or country of origin.
- Part of Azure Front Door's Web Application Firewall (WAF).
- Allows defining allow or block rules based on country/region codes.
- Crucial for compliance with data residency and access restrictions.
- Can be configured as a custom WAF rule condition.
Memory trick: To filter by land, use 'Geo-filtering' to understand the client's stand.