Question 1 of 30
A company is deploying a web application that handles sensitive customer data and is required to comply with the Payment Card Industry Data Security Standard (PCI DSS). They are considering implementing a Web Application Firewall (WAF) to protect against common web vulnerabilities. The security team is tasked with configuring WAF policies to mitigate risks such as SQL injection and cross-site scripting (XSS). Which approach should the team prioritize when configuring the WAF policies to ensure maximum protection while maintaining application performance?
Implement a positive security model that only allows known good traffic patterns and blocks everything else.
Configure the WAF to allow all traffic and only log suspicious activities for later review.
Use a negative security model that blocks known bad traffic patterns while allowing all other traffic.
Set the WAF to operate in monitoring mode only, without actively blocking any traffic.

Preparing for Microsoft AZ-700 Designing and Implementing Microsoft Azure Networking Solutions? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free