Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A company needs to protect its web applications hosted on Azure App Service from common web-based attacks such as SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities. They require a solution that filters traffic before it reaches the application, without modifying the application code. Which Azure security solution should they implement?
- AAzure Firewall
- BAzure DDoS Protection
- CAzure Network Security Groups (NSG)
- DAzure Web Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Web Application Firewall (WAF)
Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities. It filters HTTP/HTTPS traffic and protects against OWASP Top 10 threats like SQL injection and cross-site scripting.
Why the other options are wrong
- A. Azure Firewall is a managed cloud-based network security service that protects virtual network resources, but it doesn't provide application-layer filtering for web exploits like WAF.
- B. Azure DDoS Protection defends against Distributed Denial of Service attacks, which are different from application-layer web exploits.
- C. Azure Network Security Groups (NSG) filter network traffic at the network interface or subnet level based on IP addresses and ports, not specific web application attacks.
Azure Web Application Firewall (WAF)
A feature that provides centralized protection for web applications from common exploits and vulnerabilities, such as SQL injection and cross-site scripting.
- Protects against OWASP Top 10 web vulnerabilities
- Filters HTTP/HTTPS traffic at the application layer
- Can be deployed with Azure Application Gateway or Azure Front Door
Memory trick: WAF wipes out web attacks.