Courseiva

SC-100 Web Application Firewall (WAF) Practice Question

You are designing a solution to protect Azure SQL Database from SQL injection attacks. The solution must use a web application firewall (WAF) and also ensure that queries from the application are parameterized. Which two components should you include? (Choose two. Each correct answer presents part of the solution.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Application Gateway with WAF

Option C is correct because Azure Application Gateway with WAF provides a web application firewall that can inspect incoming HTTP/HTTPS traffic and block common SQL injection patterns using OWASP rule sets before requests reach the application or database. Option D is correct because parameterized queries in the application code ensure user input is treated as data rather than executable SQL, which is the primary defense against SQL injection at the application layer. Together, these two components satisfy both stated requirements: a WAF and parameterized queries. Option A, Azure SQL Database firewall rules, only controls which IP addresses or Azure services can connect to the database and does not inspect query content for injection attacks. Option B, Transparent Data Encryption (TDE), encrypts data at rest and does not prevent SQL injection or filter malicious queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure SQL Database firewall rules

    Why it's wrong here

    Azure SQL Database firewall rules restrict which client IP addresses or virtual networks can establish connections to the database. However, SQL injection is an application-layer attack that arrives through an already allowed connection; the firewall evaluates only the source address and protocol handshake, not the content of SQL statements. Therefore, it cannot distinguish a malicious query from a legitimate one and provides no injection prevention.

  • ✗

    Transparent Data Encryption (TDE)

    Why it's wrong here

    Transparent Data Encryption (TDE) encrypts the underlying database files, log files, and backups at rest using a symmetric database encryption key. It protects against theft of physical media or unauthorized access to storage, but it does not inspect or transform query text during execution. Since SQL injection manipulates the SQL command itself before it is processed, TDE has no effect on stopping injected code.

  • ✓

    Azure Application Gateway with WAF

    Why this is correct

    Azure Application Gateway with Web Application Firewall (WAF) inspects inbound HTTP/HTTPS traffic at the application layer and applies the OWASP Core Rule Set, which includes specialized SQL injection rules. It can detect and block malicious patterns in query strings, request bodies, and headers before the request reaches Azure SQL Database. This provides a centralized, cloud-managed defense layer that is particularly effective for public web applications exposing APIs or SQL-backed endpoints.

  • ✓

    Parameterized queries in the application code

    Why this is correct

    Parameterized queries (or prepared statements) force the database engine to treat user input strictly as data values, never as executable SQL syntax. By separating the SQL command structure from the input parameters, attackers cannot inject arbitrary clauses or expressions into the query. This is the most robust mitigation at the application code level because it eliminates the root cause of SQL injection rather than relying on network-level detection.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.