Protecting Internet-Facing Websites from Buffer Overflow Attacks

Security Operations

An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?

  1. NGFW
  2. WAF Source Reference Answer
  3. TLS
  4. SD-WAN

Community Votes

B
78%
A
22%

78% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between network-level security (NGFW) and application-level security (WAF), with the common trap being the selection of NGFW due to its broader capabilities rather than its specific fit for web application vulnerabilities.

A Web Application Firewall (WAF) is the optimal defense for internet-facing websites against application-layer exploits like buffer overflows, SQL injection, and XSS. The community consensus strongly favors WAF over NGFW because it operates specifically at Layer 7 to inspect HTTP/HTTPS traffic payloads.

Community Discussion (12 comments)

CookieChip 👍 16
B is the correct one B. WAF (Web Application Firewall) A. NGFW (Next-Generation Firewall) C. TLS (Transport Layer Security) D. SD-WAN (Software-Defined Wide Area Network)
Mehsotopes 👍 14 Selected: B
A Web Application Firewall (WAF) is for ensuring the security of an HTTP application like WordPress, or Magneto against threats like SQL injection, or XSS.
JackExam2025 👍 1 Selected: B
WAF is the best solution for preventing application-specific attacks like buffer overflows
Hasss 👍 1 Selected: B
web APP fireeall
AlternateEgo 👍 3 Selected: B
I can see why the "correct" answer is WAF, but the question is silly. Why use your WAF to try to block buffer overflow attacks? Why not have the application developers add or fix input validation on the web forms, which is what's really needed. How would you know what bit-length to restrict inputs to for your WAF rule without consulting the developers? And if you are consulting the developers about this, just have then fix it at the source. I'm all for defense in depth, but it doesn't seem realistic to try to block this at the WAF or NGFW.
Fatneck 👍 5 Selected: B
The answer is B and not A because it says "internet-facing website was compromised." That is specifically what WAF's are designed for. Next-Gen's operate at Layer 7 and provide application-level inspection but are designed for network level protection across services.
viktorrdlyi 👍 1 Selected: A
NGFW is much more effective then WAF.
braveheart22 👍 4 Selected: A
NGFW is the correct answer. When it comes to defending against buffer overflow attacks, a Next-Generation Firewall (NGFW) is generally more effective than a Web Application Firewall (WAF). Here's why: NGFW Capabilities: NGFWs provide deep packet inspection, advanced threat detection, and the ability to identify and block malicious traffic based on patterns and behaviors. They can also enforce security policies at the network level, which helps prevent exploitation attempts before they reach the application. WAF Limitations: While WAFs are designed to protect web applications by filtering and monitoring HTTP traffic, they primarily focus on application-layer attacks like SQL injection and cross-site scripting (XSS). Buffer overflow attacks, which often target vulnerabilities in software rather than web applications, may not be as effectively mitigated by a WAF.
JoeShmo 👍 2 Selected: A
A NGFW would better protect against buffer overflow attacks thanks to deep packet inspection and IDS/IPS. A WAF would protect better against SQL injections and XSS.
Markeze 👍 1 Selected: A
cuz its a web application fire, and it's main purpose is to protect web applications from external threats
dbrowndiver 👍 4 Selected: B
A WAF inspects incoming and outgoing web traffic to detect and block malicious payloads that may exploit application vulnerabilities, such as buffer overflows.
shady23 👍 1 Selected: B
b.WAF Web Application Firewall

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Web Application Firewall (WAF) is designed to filter, monitor, and block HTTP traffic to and from a web service, making it the ideal tool for protecting internet-facing websites. It inspects the content of web requests to detect malicious patterns associated with application-layer attacks, including buffer overflows, SQL injections, and cross-site scripting (XSS). Since the compromised asset is specifically an 'internet-facing website,' a WAF provides the necessary granular control over web traffic that general firewalls lack.

Why the Other Options Are Wrong

Next-Generation Firewalls (NGFWs) primarily operate at Layers 3 and 4, offering deep packet inspection but often lacking the sophisticated application-layer logic required to parse complex web code for specific vulnerabilities like buffer overflows without significant performance overhead or false positives. TLS (Transport Layer Security) encrypts data in transit but does not inspect payload content for malicious code or exploit attempts. SD-WAN focuses on optimizing wide area network connectivity and path selection, providing no intrinsic security features against application exploits.

Community Comment Notes

Comment [3] correctly highlights that while NGFWs have some Layer 7 capabilities, they are designed for broader network protection, whereas WAFs are specialized for web services. Comment [6] raises a valid point about input validation being the root fix, but notes that in the context of immediate deployment options listed, WAF is the best defensive measure among the choices. Several users confused NGFW with WAF, but the consensus confirms that for web-specific attacks, WAF is the standard answer.

Official Reference

Exam Strategy

Always identify the specific asset type mentioned in the scenario; if it is a 'website' or 'web application,' prioritize WAF solutions over general network firewalls. Focus on the attack vector: if it involves HTTP/HTTPS payloads (like SQLi or buffer overflows in code), look for application-layer defenses first.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide