Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

An organization is deploying a highly critical web application in Azure that requires protection against common web vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 threats. The application is exposed via an Azure Application Gateway. Which specific feature of Application Gateway should be enabled and configured to provide this protection?

  1. AWeb Application Firewall (WAF)
  2. BURL-based Routing
  3. CSession Affinity
  4. DBackend Health Probes
Show answer & explanation

Correct answer: A. Web Application Firewall (WAF)

The Web Application Firewall (WAF) feature of Azure Application Gateway provides centralized protection of your web applications from common exploits and vulnerabilities. It protects against OWASP Top 10 threats, including SQL injection and cross-site scripting.

Why the other options are wrong

  • B. URL-based routing directs traffic to different backend pools based on URL paths, not for security against web vulnerabilities.
  • C. Session affinity (sticky sessions) ensures that requests from a user session are routed to the same backend server, not a security feature.
  • D. Backend health probes monitor the health of backend instances, ensuring traffic is sent only to healthy servers, not for web vulnerability protection.

Azure Application Gateway WAF

Azure Application Gateway's Web Application Firewall (WAF) provides centralized protection for web applications from common web-based attacks and vulnerabilities, based on OWASP core rule sets.

  • Protects against OWASP Top 10 vulnerabilities.
  • Operates at Layer 7 (HTTP/S).
  • Can run in Detection or Prevention mode.
  • Integrates seamlessly with Application Gateway.

Memory trick: App Gateway WAF: Your web app's bouncer for bad requests.

More Implement platform protection questions