Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A developer is building a web API that exposes sensitive customer data. The API is hosted on Azure App Service. To protect against common web vulnerabilities such as SQL injection and cross-site scripting (XSS), which Azure service should be implemented in front of the App Service?
- AAzure CDN (Content Delivery Network)
- BAzure Application Gateway with WAF
- CAzure Load Balancer
- DAzure Front Door
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Application Gateway with WAF
Azure Application Gateway with Web Application Firewall (WAF) is specifically designed to protect web applications from common web-based attacks like SQL injection, XSS, and other OWASP Top 10 vulnerabilities. It acts as a layer 7 load balancer and provides WAF capabilities.
Why the other options are wrong
- A. Azure CDN is for caching static content at edge locations to improve performance, not for protecting against web vulnerabilities.
- C. Azure Load Balancer operates at layer 4 and distributes network traffic; it does not provide application-level protection against web vulnerabilities.
- D. Azure Front Door is a global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. While it has WAF capabilities, Application Gateway is a more direct and common choice for protecting a single App Service within a region.
Azure Application Gateway with WAF
A web traffic load balancer that enables you to manage traffic to your web applications, offering a Web Application Firewall (WAF) to protect against common web vulnerabilities.
- Operates at Layer 7 (HTTP/HTTPS)
- Protects against OWASP Top 10 vulnerabilities
- Integrates with Azure Monitor for logging and diagnostics
Memory trick: App Gateway WAF: Your web app's bouncer.