Protect Azure App Service Web Application with WAF and SQL Encryption
You are designing a solution to protect an Azure App Service web application from common web attacks like SQL injection and cross-site scripting. What should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Web Application Firewall (WAF) policy on Azure Front Door
Azure Web Application Firewall (WAF) policy on Azure Front Door (option C) is correct because WAF is specifically designed to inspect HTTP/HTTPS traffic and block Layer 7 attacks such as SQL injection and cross-site scripting using managed rule sets (OWASP rules). Azure Front Door provides global edge delivery and integrates WAF policies directly, making it the appropriate choice for protecting a public web application. Azure Firewall (A) is a Layer 3-4 network firewall with limited FQDN filtering and does not provide OWASP-style web attack protection. Azure DDoS Protection (B) mitigates volumetric and protocol-level attacks, not application-layer injection or scripting attacks. NSGs (D) filter traffic by IP, port, and protocol at the network layer and cannot inspect HTTP payloads for SQLi or XSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall
Why it's wrong here
Azure Firewall is a network-layer, stateful filtering service operating on IP, port and FQDN rules; it does not inspect HTTP payloads for SQL injection or cross-site scripting. It is tempting as a perimeter control, but application-layer attack protection requires a Web Application Firewall on Azure Front Door or Application Gateway.
- ✗
Azure DDoS Protection
Why it's wrong here
DDoS Protection absorbs volumetric and protocol-layer floods at the network edge; it inspects no HTTP payload, so SQL injection and XSS requests pass through untouched. It is tempting because it genuinely defends public Azure endpoints, and would be correct when the threat is traffic flooding rather than application-layer input manipulation.
- ✓
Azure Web Application Firewall (WAF) policy on Azure Front Door
Why this is correct
A WAF policy on Azure Front Door inspects HTTP traffic at the edge, applying managed rule sets that block SQL injection and cross-site scripting before requests reach App Service, satisfying the requirement to protect against common web attacks.
- ✗
Network Security Groups (NSGs) on the subnet
Why it's wrong here
NSGs filter traffic by IP address, port and protocol at layers 3–4, so they cannot parse HTTP requests to detect injection or script payloads. They are tempting because subnet-level filtering is a real control, and would be correct for restricting which source addresses or ports may reach the App Service.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.