Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global enterprise is designing its multi-region Azure architecture to host critical web applications. The applications must be protected against common web vulnerabilities, such as SQL injection and cross-site scripting (XSS), and also from large-scale DDoS attacks. The solution needs to provide global traffic routing, caching, and SSL offloading capabilities, with centralized management of web application firewall (WAF) policies across all regions. Which Azure service combination should the architect recommend to meet these requirements comprehensively?

  1. AAzure Application Gateway with WAF tier
  2. BAzure Front Door with WAF policy
  3. CAzure Firewall Premium
  4. DAzure CDN with Azure DDoS Protection Standard
Show answer & explanation

Correct answer: B. Azure Front Door with WAF policy

Azure Front Door provides global traffic routing, caching, and SSL offloading. When combined with a WAF policy, it offers centralized protection against common web vulnerabilities and integrates with Azure DDoS Protection for large-scale attacks. This combination meets all requirements for global, comprehensive web application security and performance.

Why the other options are wrong

  • A. Azure Application Gateway with WAF tier is a regional service, not global, and while it provides WAF and SSL offloading, it lacks global traffic routing and caching capabilities for multi-region setups.
  • C. Azure Firewall Premium is a stateful firewall for network traffic, offering advanced threat protection at the network layer, but it does not provide global traffic routing, caching, or WAF capabilities specifically for HTTP/S traffic.
  • D. Azure CDN caches content globally for performance but does not include WAF capabilities for application-layer attacks. Azure DDoS Protection Standard protects against network-layer attacks but needs to be combined with a WAF for application-layer threats.

Azure Front Door with WAF

A global, scalable entry-point that provides fast, secure, and highly available web applications by combining global traffic routing, caching, SSL offloading, and a Web Application Firewall (WAF).

  • Global traffic management and acceleration.
  • Protects against common web vulnerabilities (OWASP Top 10).
  • Integrates with Azure DDoS Protection Standard for network-layer attacks.

Memory trick: Front Door with WAF is your global bouncer, protecting web apps from threats and speeding up delivery.

More Design security for applications and data questions