Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy

A company is developing a new web API that exposes sensitive customer data. The API is hosted on an Azure App Service. To protect against common web vulnerabilities like SQL injection and cross-site scripting (XSS), and to inspect incoming traffic for malicious patterns, the security team requires a Web Application Firewall (WAF) to be deployed in front of the API. Which Azure service provides a WAF capability that can protect an Azure App Service?

  1. AAzure Application Gateway with WAF
  2. BAzure Traffic Manager
  3. CAzure CDN (Content Delivery Network)
  4. DAzure Load Balancer
Show answer & explanation

Correct answer: A. Azure Application Gateway with WAF

Azure Application Gateway with its Web Application Firewall (WAF) capability is specifically designed to protect web applications from common web-based attacks like SQL injection and XSS. It operates at Layer 7 and can be deployed in front of Azure App Service to inspect and filter incoming traffic.

Why the other options are wrong

  • B. Azure Traffic Manager is a DNS-based traffic load balancer that distributes traffic across global Azure regions, but it does not offer WAF capabilities.
  • C. Azure CDN is used for content caching and delivery, not for web application firewall protection.
  • D. Azure Load Balancer operates at Layer 4 (TCP/UDP) and distributes network traffic. It does not provide Layer 7 WAF protection.

Azure Application Gateway WAF

A Web Application Firewall (WAF) capability integrated into Azure Application Gateway, providing centralized protection for web applications against common exploits and vulnerabilities.

  • Operates at Layer 7 (HTTP/HTTPS).
  • Protects against OWASP Top 10 vulnerabilities (e.g., SQL injection, XSS).
  • Can be deployed in front of various backend services, including Azure App Service.

Memory trick: App Gateway WAF: The bouncer for your web applications.

More Implement Azure security questions