Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A security engineer is tasked with implementing a solution to protect an organization's Azure resources from common web-based attacks such as SQL injection and cross-site scripting. The solution must be easily deployable and scalable within Azure. Which Azure security capability should the engineer choose?

  1. AAzure Network Security Groups (NSGs)
  2. BAzure DDoS Protection Standard
  3. CAzure Web Application Firewall (WAF)
  4. DAzure Firewall
Show answer & explanation

Correct answer: C. Azure Web Application Firewall (WAF)

Azure Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and cross-site scripting. It operates at Layer 7 (application layer) and can be integrated with Azure Application Gateway, Azure Front Door, or Azure CDN.

Why the other options are wrong

  • A. Azure Network Security Groups (NSGs) filter network traffic to and from Azure resources at Layer 4 (transport layer) and below, not application-layer attacks like SQL injection.
  • B. Azure DDoS Protection Standard protects against Distributed Denial of Service attacks, not web application specific exploits.
  • D. Azure Firewall is a managed cloud-based network security service that protects Azure Virtual Network resources, but it's a general-purpose firewall, not specifically for web application attacks.

Azure Web Application Firewall (WAF)

A service that provides centralized protection of web applications from common exploits and vulnerabilities, such as SQL injection and cross-site scripting.

  • Operates at Layer 7 (application layer).
  • Protects against OWASP Top 10 vulnerabilities.
  • Can be integrated with Application Gateway, Front Door, or CDN.

Memory trick: Web App Firewall: Shield Against Web Worms.

More Describe the capabilities of Microsoft Security solutions questions