Courseiva

Protect Azure App Service Web Application with WAF and SQL Encryption

You are designing a solution to protect an Azure App Service web application from common web attacks like SQL injection and cross-site scripting. What should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Web Application Firewall (WAF) policy on Azure Front Door

Azure Web Application Firewall (WAF) policy on Azure Front Door (option C) is correct because WAF is specifically designed to inspect HTTP/HTTPS traffic and block Layer 7 attacks such as SQL injection and cross-site scripting using managed rule sets (OWASP rules). Azure Front Door provides global edge delivery and integrates WAF policies directly, making it the appropriate choice for protecting a public web application. Azure Firewall (A) is a Layer 3-4 network firewall with limited FQDN filtering and does not provide OWASP-style web attack protection. Azure DDoS Protection (B) mitigates volumetric and protocol-level attacks, not application-layer injection or scripting attacks. NSGs (D) filter traffic by IP, port, and protocol at the network layer and cannot inspect HTTP payloads for SQLi or XSS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a network-layer, stateful filtering service operating on IP, port and FQDN rules; it does not inspect HTTP payloads for SQL injection or cross-site scripting. It is tempting as a perimeter control, but application-layer attack protection requires a Web Application Firewall on Azure Front Door or Application Gateway.

  • ✗

    Azure DDoS Protection

    Why it's wrong here

    DDoS Protection absorbs volumetric and protocol-layer floods at the network edge; it inspects no HTTP payload, so SQL injection and XSS requests pass through untouched. It is tempting because it genuinely defends public Azure endpoints, and would be correct when the threat is traffic flooding rather than application-layer input manipulation.

  • ✓

    Azure Web Application Firewall (WAF) policy on Azure Front Door

    Why this is correct

    A WAF policy on Azure Front Door inspects HTTP traffic at the edge, applying managed rule sets that block SQL injection and cross-site scripting before requests reach App Service, satisfying the requirement to protect against common web attacks.

  • ✗

    Network Security Groups (NSGs) on the subnet

    Why it's wrong here

    NSGs filter traffic by IP address, port and protocol at layers 3–4, so they cannot parse HTTP requests to detect injection or script payloads. They are tempting because subnet-level filtering is a real control, and would be correct for restricting which source addresses or ports may reach the App Service.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.