Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsEasy
A small non-profit organization is moving its website and donor database to Azure. They have a limited budget but need to ensure their web applications are protected against common web-based attacks like SQL injection and cross-site scripting. Which Azure security service should they prioritize for this purpose?
- AAzure Security Center (Standard Tier)
- BAzure Key Vault
- CAzure Front Door with Web Application Firewall (WAF)
- DAzure DDoS Protection Standard
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Front Door with Web Application Firewall (WAF)
Azure Front Door with Web Application Firewall (WAF) provides centralized protection for web applications against common exploits and vulnerabilities, making it ideal for protecting websites and databases from attacks like SQL injection and cross-site scripting.
Why the other options are wrong
- A. Azure Security Center (Standard Tier) provides broader cloud security posture management and threat protection but doesn't specifically focus on application-layer WAF capabilities.
- B. Azure Key Vault is used for securely storing cryptographic keys and other secrets, not for protecting web applications from common exploits.
- D. Azure DDoS Protection Standard protects against distributed denial-of-service attacks, not application-layer exploits.
Azure Front Door WAF
A cloud-native web application firewall that protects web applications from common web-based attacks.
- Integrated with Azure Front Door for global traffic routing.
- Protects against OWASP Top 10 vulnerabilities.
- Offers managed rulesets and custom rules.
Memory trick: Front Door WAF guards web apps from common web attacks.