Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A security engineer is tasked with implementing a solution to protect an organization's Azure-hosted web applications from common web-based attacks, such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. The solution must integrate seamlessly with Azure Application Gateway. Which Azure security solution should be deployed?

  1. ANetwork Security Groups (NSG)
  2. BAzure Web Application Firewall (WAF)
  3. CAzure Firewall
  4. DAzure DDoS Protection
Show answer & explanation

Correct answer: B. Azure Web Application Firewall (WAF)

Azure Web Application Firewall (WAF) provides centralized protection of web applications from common exploits and vulnerabilities. It can be deployed with Azure Application Gateway to protect web applications.

Why the other options are wrong

  • A. Network Security Groups (NSG) provide basic network layer filtering (ports, protocols, IPs), not application layer attack protection.
  • C. Azure Firewall is a managed network security service that protects Azure Virtual Network resources, but it's not specialized for web application attacks.
  • D. Azure DDoS Protection protects against Distributed Denial of Service attacks, not specific web-based exploits.

Azure Web Application Firewall (WAF)

A cloud-native service that protects web applications from common web-based exploits and vulnerabilities such as SQL injection, cross-site scripting, and other OWASP Top 10 risks.

  • Protects web applications
  • Defends against OWASP Top 10 attacks
  • Integrates with Application Gateway or Front Door

Memory trick: WAF is your web app's bouncer for bad traffic.

More Describe the capabilities of Microsoft Security solutions questions