ITPEC FE Subject A April 2025 Question 32
ITPEC FE Subject A April 2025 — Question 32 of 60
WAF (Web Application Firewall) — WAF inspects and filters HTTP/HTTPS traffic between clients and a web application.
A WAF sits in front of a web server and analyzes incoming HTTP requests against a set of rules to block attacks like SQL injection, XSS, and other OWASP Top 10 threats.
Why not others:
- (a) Encrypting data and controlling access describes SSL/TLS or access control mechanisms, not a WAF
- (c) Managing authentication and authorization is the job of IAM (Identity and Access Management) systems
- (d) Scanning malware on a web server describes antivirus/anti-malware software, not a WAF
Key rule: WAF = HTTP-level firewall that inspects and filters web traffic to protect against application-layer attacks.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.