Attackers are targeting the citizen portal with HTTP application attacks such as injection and abusive web requests. Which control is the best fit for that threat layer?
Select an answer to reveal the explanation.
Short Explanation
Web app punches need a web app shield—that is the WAF’s lane. A plain port firewall does not speak HTTP injection. Mantraps protect doors, not form fields.
Full Explanation
WAFs are designed to inspect and mitigate HTTP/HTTPS application-layer attacks against web portals. Traditional Layer 4 firewalls lack deep application request awareness for many injection and abusive web patterns. Physical entry controls and disabling TLS do not address application-layer portal attacks and may worsen exposure.