Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
An organization is deploying a highly critical web application in Azure that requires protection against common web-based attacks such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. The application is hosted on Azure App Service, and traffic needs to be load-balanced and routed securely. Which Azure service should be implemented to provide this specific layer 7 protection?
- AAzure Application Gateway with WAF
- BAzure Firewall
- CNetwork Security Groups (NSGs)
- DAzure DDoS Protection Standard
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Application Gateway with WAF
Azure Application Gateway with Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities. It operates at Layer 7 (HTTP/HTTPS) and is specifically designed to detect and prevent attacks like SQL injection and cross-site scripting, while also providing load balancing.
Why the other options are wrong
- B. Azure Firewall provides Layer 3/4 and some Layer 7 (FQDN) filtering but does not offer deep web application attack protection like SQL injection or XSS.
- C. NSGs operate at Layer 3/4 and provide basic packet filtering, not web application layer protection.
- D. Azure DDoS Protection Standard protects against distributed denial of service attacks, which is different from web application layer attacks like SQL injection.
Azure Application Gateway WAF
A web application firewall (WAF) that protects web applications from common web-based attacks. It's integrated with Azure Application Gateway, providing Layer 7 load balancing and security.
- Protects against OWASP Top 10 vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS).
- Can be deployed with custom WAF rules and managed rule sets.
Memory trick: WAF is the bouncer for your web app, keeping bad requests out.