A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?
A WAF operates at the application layer, terminating and inspecting HTTP and HTTPS requests, applying rule sets such as the OWASP Core Rule Set, and blocking malicious traffic before it reaches the web server. This matches the described inline inspection and blocking requirement.
Why this answer
A Web Application Firewall (WAF) is specifically designed to inspect HTTP and HTTPS traffic at Layer 7, apply rule sets such as the OWASP ModSecurity Core Rule Set, and block malicious requests like SQL injection, XSS, and CSRF before they reach the web server. It understands web protocols and can enforce positive/negative security models based on HTTP headers, cookies, and payloads. This matches the described requirement exactly.
How to eliminate wrong answers
Option A is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not to inspect and block production HTTP/HTTPS traffic. Option B is wrong because an IPS inspects network traffic for known attack signatures and anomalies at Layers 3-7 but is not specialized for HTTP/HTTPS application-layer semantics like OWASP rules; it lacks the deep HTTP parsing and session awareness of a WAF. Option D is wrong because a stateful firewall tracks connection state at Layers 3-4 and cannot inspect HTTP payloads or apply OWASP rules — it only permits or denies based on IP, port, and connection state.