One site is regional-only behind Application Gateway; another is global behind Front Door. Where should the security engineer attach WAF policies?
Select an answer to reveal the explanation.
Short Explanation
WAF is a policy that rides on the host you already chose—Application Gateway WAF_v2 regionally, Front Door WAF globally. Firewall IDPS is useful, but it isn’t that WAF.
Full Explanation
Azure WAF policies associate with Application Gateway (WAF_v2), Azure Front Door, or classic CDN hosts matching the architecture. Regional-only sites use Application Gateway WAF; global Front Door sites use Front Door WAF. Azure Firewall Premium IDPS is not a substitute for those WAF associations. WAF is not deployed as an arbitrary standalone VM product in this skill. NSG allow rules alone do not provide OWASP managed-rule WAF protection.