Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A developer is building a web API that exposes sensitive customer data. The API is hosted on Azure App Service. To protect against common web vulnerabilities such as SQL injection and cross-site scripting (XSS), which Azure service should be implemented in front of the App Service?

  1. AAzure CDN (Content Delivery Network)
  2. BAzure Application Gateway with WAF
  3. CAzure Load Balancer
  4. DAzure Front Door
Show answer & explanation

Correct answer: B. Azure Application Gateway with WAF

Azure Application Gateway with Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection, XSS, and other OWASP Top 10 vulnerabilities. It acts as a layer 7 load balancer and provides WAF capabilities.

Why the other options are wrong

  • A. Azure CDN is for caching static content at edge locations to improve performance, not for protecting against web vulnerabilities.
  • C. Azure Load Balancer operates at layer 4 and distributes network traffic; it does not provide application-level protection against web vulnerabilities.
  • D. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. While it has WAF capabilities, Application Gateway is a more direct and common choice for protecting a single App Service within a region.

Azure Application Gateway with WAF

A web traffic load balancer that enables you to manage traffic to your web applications, offering a Web Application Firewall (WAF) to protect against common web vulnerabilities.

  • Operates at Layer 7 (HTTP/HTTPS)
  • Protects against OWASP Top 10 vulnerabilities
  • Integrates with Azure Monitor for logging and diagnostics

Memory trick: App Gateway WAF: Your web app's bouncer.

More Implement Azure security questions