Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A global e-commerce company operates several web applications in Azure. They need to protect these applications from common web-based attacks such as SQL injection, cross-site scripting (XSS), and bot attacks. Additionally, they require centralized management of these protections with the ability to define custom rules and geo-filtering. Which Azure service should they implement?

  1. AAzure Application Gateway with WAF
  2. BAzure Network Security Groups (NSGs)
  3. CAzure Firewall
  4. DAzure DDoS Protection Standard
Show answer & explanation

Correct answer: A. Azure Application Gateway with WAF

Azure Application Gateway with its Web Application Firewall (WAF) capability is specifically designed to protect web applications from common web-based attacks, including SQL injection and XSS. It also supports custom WAF rules and can integrate with Azure Front Door for geo-filtering, fulfilling the requirements for centralized management and protection.

Why the other options are wrong

  • B. NSGs provide basic network layer filtering (IP, port, protocol) but cannot protect against web-specific attacks like SQL injection or XSS.
  • C. Azure Firewall is a network firewall that protects against network-level threats but does not inspect or protect against web application layer attacks.
  • D. Azure DDoS Protection Standard protects against volumetric denial-of-service attacks but does not protect against application-layer attacks like SQL injection or XSS.

Azure Application Gateway WAF

Azure Application Gateway with Web Application Firewall (WAF) provides centralized protection for web applications from common exploits and vulnerabilities.

  • Protects against OWASP Top 10 vulnerabilities.
  • Supports custom WAF rules and managed rule sets.
  • Can be deployed with Azure Front Door for global coverage and geo-filtering.
  • Operates at Layer 7 (application layer).

Memory trick: To shield my web app, I need a 'Gateway' with a 'WAF' bodyguard.

More Implement platform protection questions