Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium

A company is concerned about its Azure resources being exposed to common web vulnerabilities like SQL injection and cross-site scripting. They need a service that can protect their web applications hosted on Azure from these types of attacks. Which Azure security capability should they implement?

  1. AAzure Front Door
  2. BAzure Firewall
  3. CAzure DDoS Protection
  4. DAzure Web Application Firewall (WAF)
Show answer & explanation

Correct answer: D. Azure Web Application Firewall (WAF)

Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities such as SQL injection, cross-site scripting, and other OWASP top 10 risks.

Why the other options are wrong

  • A. Azure Front Door is a scalable, secure entry point for fast global web applications, offering caching and load balancing, but WAF is a specific feature within it or Application Gateway.
  • B. Azure Firewall provides network-level threat protection for Azure Virtual Network resources, not specifically layer 7 web application attacks.
  • C. Azure DDoS Protection defends against Distributed Denial of Service attacks, not web application vulnerabilities.

Azure Web Application Firewall (WAF)

A feature of Azure Application Gateway and Azure Front Door that helps protect web applications from common web-based attacks like SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities.

  • Protects web applications at Layer 7.
  • Defends against OWASP Top 10 vulnerabilities.
  • Can be integrated with Application Gateway or Front Door.

Memory trick: WAF guards the web apps from nasty attacks.

More Describe the capabilities of Microsoft Security solutions questions