Web Application Firewall (WAF)
A firewall that inspects HTTP and HTTPS traffic to a web application at layer 7 and blocks requests that match attack patterns or break the application's expected behaviour.
A Web Application Firewall sits in front of a web application and inspects its HTTP and HTTPS requests and responses at the application layer. It blocks requests that match known attack patterns, such as SQL injection or cross-site scripting, or that fall outside a model of what the application should receive. It may run as an appliance, a reverse proxy, a server module or a cloud service. To read the content, it must see traffic after TLS is removed.
A conventional firewall decides on addresses, ports and connection state, and cannot tell a normal form submission from an injection attempt on the same port. A next-generation firewall identifies applications across many protocols; a WAF specialises in the web and in the logic of one application. A WAF does not fix vulnerable code. It is commonly used as a compensating control or a virtual patch while the code is corrected, and PCI DSS v4.0 (requirement 6.4.2, mandatory from 31 March 2025) requires an automated solution of this kind in front of public-facing web applications.
Exam relevance: a scenario is likely to describe web attacks against an application whose code cannot be changed quickly and ask for the best immediate control. Candidates are expected to recognise the WAF as that control, and to keep it apart from secure coding, which removes the flaw it only screens.