Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Endpoint, Host & Application

WAF

Web Application Firewall

Filters HTTP traffic to protect web apps from injection and similar attacks.

A WAF inspects HTTP and HTTPS requests at Layer 7 to block web attacks such as SQL injection and cross-site scripting, acting on application-aware rules rather than ports and addresses. It can run in detection or blocking mode and is often tuned around the OWASP Top 10. Unlike a traditional network firewall, it understands web payloads and sessions. It is a compensating control and does not replace fixing insecure application code.

Related terms

Looking WAF up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.