Your SOC sees two alerts: one for SQL injection attempts against an internet-facing login page, and one for malformed TCP options flooding a DMZ segment. Which control is best positioned to inspect and block the SQL injection attempts before they reach application logic?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: a WAF sits at the front door of your web app and reads the actual request, not just the packet. SQL injection lives in parameters and payloads, so the WAF can block it before the code touches it. Don't confuse that with an IPS, which is great at network abuse but blind to application logic.
Full Explanation
A WAF operates at the application layer and is designed to parse HTTP or HTTPS requests, evaluate methods, URLs, headers, cookies, and parameter values, then apply signatures or behavioral rules to block attacks such as SQL injection, XSS, and command injection. In a hybrid SOC, it is the control that sees the web request as a web request, so it can stop malicious input before the application backend consumes it. A network IPS analyzes traffic patterns, protocol conformance, and known network-layer abuse, but it does not reliably understand application semantics, so it may miss or mishandle encoded payloads hidden inside legitimate HTTP. An EDR agent protects endpoints by monitoring processes, files, registry changes, and lateral movement after code executes, making it too late and too host-focused for pre-application input validation. A SIEM correlation rule can alert on suspicious indicators across logs, but it generally does not inspect live request bodies or enforce inline blocking. Exam caveat: map controls by layer and function, not by brand or acronym. Operational check: confirm WAF logs show blocked SQL injection signatures and verify the IPS policy is tuned for protocol anomalies rather than web parameter attacks.