Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
A company is concerned about its Azure resources being exposed to common web vulnerabilities like SQL injection and cross-site scripting. They need a service that can protect their web applications hosted on Azure from these types of attacks. Which Azure security capability should they implement?
- AAzure Front Door
- BAzure Firewall
- CAzure DDoS Protection
- DAzure Web Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Web Application Firewall (WAF)
Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities such as SQL injection, cross-site scripting, and other OWASP top 10 risks.
Why the other options are wrong
- A. Azure Front Door is a scalable, secure entry point for fast global web applications, offering caching and load balancing, but WAF is a specific feature within it or Application Gateway.
- B. Azure Firewall provides network-level threat protection for Azure Virtual Network resources, not specifically layer 7 web application attacks.
- C. Azure DDoS Protection defends against Distributed Denial of Service attacks, not web application vulnerabilities.
Azure Web Application Firewall (WAF)
A feature of Azure Application Gateway and Azure Front Door that helps protect web applications from common web-based attacks like SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities.
- Protects web applications at Layer 7.
- Defends against OWASP Top 10 vulnerabilities.
- Can be integrated with Application Gateway or Front Door.
Memory trick: WAF guards the web apps from nasty attacks.