Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
A security engineer is tasked with implementing a solution to protect an organization's Azure resources from common web-based attacks such as SQL injection and cross-site scripting. The solution must be easily deployable and scalable within Azure. Which Azure security capability should the engineer choose?
- AAzure Network Security Groups (NSGs)
- BAzure DDoS Protection Standard
- CAzure Web Application Firewall (WAF)
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Web Application Firewall (WAF)
Azure Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection and cross-site scripting. It operates at Layer 7 (application layer) and can be integrated with Azure Application Gateway, Azure Front Door, or Azure CDN.
Why the other options are wrong
- A. Azure Network Security Groups (NSGs) filter network traffic to and from Azure resources at Layer 4 (transport layer) and below, not application-layer attacks like SQL injection.
- B. Azure DDoS Protection Standard protects against Distributed Denial of Service attacks, not web application specific exploits.
- D. Azure Firewall is a managed cloud-based network security service that protects Azure Virtual Network resources, but it's a general-purpose firewall, not specifically for web application attacks.
Azure Web Application Firewall (WAF)
A service that provides centralized protection of web applications from common exploits and vulnerabilities, such as SQL injection and cross-site scripting.
- Operates at Layer 7 (application layer).
- Protects against OWASP Top 10 vulnerabilities.
- Can be integrated with Application Gateway, Front Door, or CDN.
Memory trick: Web App Firewall: Shield Against Web Worms.