An organization purchased a critical business application containing sensitive data. The organization would like to ensure that the application is not exploited by common data exfiltration attacks. Which of the following approaches would best help to fulfill this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: WAF.
Why this is the answer
A Web Application Firewall (WAF) is the best approach because it specifically protects web applications from common attacks, including those used for data exfiltration. WAFs analyze HTTP/S traffic, detect malicious patterns (like SQL injection or cross-site scripting), and block them before they reach the application. URL scanning primarily checks for malicious links or content within URLs, not direct application vulnerabilities. A reverse proxy can offer some protection by obscuring the backend server and load balancing, but it doesn't provide the deep application-layer inspection and attack mitigation capabilities of a WAF. Network Access Control (NAC) focuses on device authentication and authorization to the network, not on protecting specific applications from web-based attacks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed