350-201 Question 115
Single answerA company is deploying a new web-based application that handles sensitive customer data. The security team wants to ensure that the application is protected against common threats such as SQL injection and cross-site scripting (XSS). Which Cisco technology can be used to provide application-layer security and enforce security policies for this application?
- A
Cisco Secure Firewall with Application Visibility and Control (AVC)
- B
Cisco Umbrella Secure Internet Gateway (SIG)
- C
Cisco Secure Workload (formerly Tetration)
- D
Cisco Secure Web Appliance (formerly WSA)
Show answer and explanation
Correct answer: A
Explanation
Cisco Secure Firewall with Application Visibility and Control (AVC) is the correct choice for protecting web-based applications at the application layer. It provides advanced features to detect and mitigate application-layer threats, including SQL injection and XSS attacks. Other options focus on different layers or aspects of security but do not directly address application-layer protections.
- A. Correct.
Cisco Secure Firewall with Application Visibility and Control (AVC) provides application-layer security by identifying and controlling application traffic. It can enforce security policies and protect against threats like SQL injection and XSS.
- B. Incorrect.
Cisco Umbrella Secure Internet Gateway (SIG) is primarily focused on DNS-layer security and providing secure internet access. It does not offer deep application-layer protections like SQL injection or XSS prevention.
- C. Incorrect.
Cisco Secure Workload (formerly Tetration) focuses on workload security and micro-segmentation, not application-layer threat prevention.
- D. Incorrect.
Cisco Secure Web Appliance (formerly WSA) is designed for web filtering and malware protection but does not specialize in protecting web-based applications against SQL injection or XSS.