Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is deploying a new web application in Azure and needs to secure it against common web attacks like SQL injection and cross-site scripting. You need to configure a solution that provides centralized protection at the network edge. Which Azure service should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Web Application Firewall (WAF) on Azure Application Gateway

Azure Web Application Firewall (WAF) on Azure Application Gateway is correct because it provides centralized, edge-level protection specifically against Layer 7 web attacks such as SQL injection and cross-site scripting (XSS) using OWASP rule sets. It inspects HTTP/HTTPS traffic at the application layer and can be attached to Application Gateway to filter malicious requests before they reach the web application. NSGs operate at Layers 3/4 and only filter traffic by IP, port, and protocol, so they cannot detect SQL injection or XSS payloads. Azure DDoS Protection mitigates volumetric and protocol-level denial-of-service attacks, not application-layer injection or scripting attacks. Azure Firewall is a stateful Layer 3-7 network firewall with FQDN and threat-intelligence filtering, but it does not provide the dedicated OWASP-based web attack inspection that WAF does.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Web Application Firewall (WAF) on Azure Application Gateway

    Why this is correct

    Azure Web Application Firewall on Application Gateway inspects HTTP traffic at the edge and applies managed rule sets that block SQL injection and cross-site scripting. Terminating at the gateway gives the centralised, network-edge protection the scenario requires.

  • ✗

    Network Security Groups (NSGs)

    Why it's wrong here

    NSGs filter traffic by IP address, port and protocol at layer 3/4, so they cannot inspect HTTP payloads to detect SQL injection or cross-site scripting. They are tempting because they are the default Azure network control, and would be correct for restricting which subnets or hosts may reach the application.

  • ✗

    Azure DDoS Protection

    Why it's wrong here

    Azure DDoS Protection absorbs volumetric and protocol-layer floods; it performs no inspection of HTTP request content, so SQL injection and cross-site scripting pass through untouched. It is tempting because it is an edge protection service, and would be correct when the requirement is resilience against distributed denial-of-service attacks.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall provides layer 3–7 filtering with FQDN and threat-intelligence rules, but its signature set does not cover application-layer web exploits such as SQL injection or cross-site scripting. It is tempting as Azure's centralised edge security service, and would be correct for egress filtering and network-level threat rules.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.