An organization recently started hosting a new service that customers access through a web portal. A security engineer needs to add to the existing security devices a new solution to protect this new service. Which of the following is the engineer most likely to deploy?
Choose an answer
Tap an option to check your answer.
Correct answer: WAF.
Why this is the answer
A Web Application Firewall (WAF) is specifically designed to protect web applications by filtering, monitoring, and blocking malicious HTTP traffic to and from a web service. Since the organization is hosting a new service accessed through a web portal, a WAF is the most appropriate solution to defend against web-specific attacks like SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities. A Layer 4 firewall operates at the transport layer and primarily controls traffic based on IP addresses and ports, offering general network protection but lacking application-layer awareness for web attacks. An NGFW (Next-Generation Firewall) offers deeper packet inspection and some application awareness but is a broader solution; a WAF is more specialized for web portals. A UTM (Unified Threat Management) device combines multiple security functions but may not offer the specialized, in-depth web application protection of a dedicated WAF.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed