Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
WAF with Application Gateway
📖 Scenario: You are setting up a secure web application in Azure. To protect it from common web attacks, you will configure a Web Application Firewall (WAF) using Azure Application Gateway.This project guides you through creating the necessary resources step-by-step.
🎯 Goal: Build an Azure Application Gateway with WAF enabled to protect your web app from threats.
📋 What You'll Learn
Create a resource group named MyResourceGroup
Create a virtual network named MyVNet with a subnet AppGatewaySubnet
Create an Application Gateway named MyAppGateway with WAF enabled
Configure the Application Gateway with a frontend IP, backend pool, HTTP settings, and listener
💡 Why This Matters
🌍 Real World
Web applications need protection from attacks like SQL injection and cross-site scripting. Azure Application Gateway with WAF helps secure apps by filtering malicious traffic.
💼 Career
Cloud engineers and security specialists use Application Gateway and WAF to build secure, scalable web infrastructures in Azure.
Progress0 / 4 steps
1
Create Resource Group and Virtual Network
Write Azure CLI commands to create a resource group called MyResourceGroup in eastus and a virtual network called MyVNet with address prefix 10.0.0.0/16 and a subnet named AppGatewaySubnet with address prefix 10.0.1.0/24.
Azure
Hint
Use az group create to make the resource group and az network vnet create to make the virtual network with subnet.
2
Create Public IP for Application Gateway
Write an Azure CLI command to create a public IP address named MyAppGatewayPublicIP in the resource group MyResourceGroup with SKU Standard and allocation method Static.
Azure
Hint
Use az network public-ip create with the correct name, SKU, and allocation method.
3
Create Application Gateway with WAF Enabled
Write an Azure CLI command to create an Application Gateway named MyAppGateway in resource group MyResourceGroup with WAF_v2 SKU, WAF enabled, using the subnet AppGatewaySubnet in virtual network MyVNet, and the public IP MyAppGatewayPublicIP. Use capacity 2 and HTTP settings with port 80.
Azure
Hint
Use az network application-gateway create with WAF_v2 SKU and enable WAF in prevention mode.
4
Configure Listener and Routing Rules
Write Azure CLI commands to create a listener named appGatewayHttpListener on frontend IP appGatewayFrontendIP and frontend port 80, and create a routing rule named rule1 that connects the listener to the backend pool appGatewayBackendPool with backend HTTP settings appGatewayBackendHttpSettings.
Azure
Hint
Use az network application-gateway http-listener create and az network application-gateway rule create to set up listener and routing rule.
Practice
(1/5)
1. What is the main purpose of enabling WAF (Web Application Firewall) on an Azure Application Gateway?
easy
A. To provide a database backup solution
B. To protect web applications from common web attacks like SQL injection and cross-site scripting
C. To increase the speed of the web application by caching content
D. To monitor network traffic at the virtual network level
Solution
Step 1: Understand WAF's role
WAF is designed to protect web apps by filtering and monitoring HTTP traffic to block common attacks.
Step 2: Compare options
Only To protect web applications from common web attacks like SQL injection and cross-site scripting describes protection from web attacks, which is the core function of WAF.
Final Answer:
To protect web applications from common web attacks like SQL injection and cross-site scripting -> Option B
Quick Check:
WAF protects web apps = C [OK]
Hint: WAF blocks web attacks, not speeds or backups [OK]
Common Mistakes:
Confusing WAF with caching or backup services
Thinking WAF monitors network traffic broadly
Assuming WAF improves app speed
2. Which of the following is the correct way to enable WAF on an Azure Application Gateway using ARM template syntax?
But the WAF is not blocking malicious requests. What is the most likely cause?
medium
A. The Application Gateway is missing a listener configuration
B. The SKU name "WAF_v2" does not support prevention mode
C. The WAF policy is not associated with the Application Gateway
D. The firewallMode should be set to Detection to block requests
Solution
Step 1: Check WAF policy association
Even if WAF is enabled, it must have a WAF policy linked to enforce rules and block threats.
Step 2: Validate other options
Listener is required but unrelated to blocking; prevention mode blocks; WAF_v2 supports prevention mode.
Final Answer:
The WAF policy is not associated with the Application Gateway -> Option C
Quick Check:
WAF policy association needed to block = D [OK]
Hint: WAF needs policy linked to block threats [OK]
Common Mistakes:
Confusing detection and prevention modes
Forgetting to associate WAF policy
Assuming SKU limits prevention mode
5. You want to protect your web app with Azure Application Gateway WAF in prevention mode but also need to monitor false positives before blocking. What is the best approach to achieve this?
hard
A. Use Basic SKU Application Gateway with WAF enabled
B. Enable WAF in prevention mode immediately and block all detected threats
C. Disable WAF and rely on network security groups for protection
D. Enable WAF in detection mode first, review logs, then switch to prevention mode
Solution
Step 1: Understand prevention vs detection modes
Prevention mode blocks threats immediately; detection mode only logs them for review.
Step 2: Plan safe deployment
Start with detection mode to identify false positives, then switch to prevention to block real threats safely.
Final Answer:
Enable WAF in detection mode first, review logs, then switch to prevention mode -> Option D
Quick Check:
Detect first, then prevent = A [OK]
Hint: Detect first, then switch to prevention mode [OK]
Common Mistakes:
Blocking immediately without monitoring false positives
Disabling WAF and relying on unrelated protections