WAAS Flashcards

1
Q

What are the major WAAS capabilities? (8)

A
  1. OWASP Top-10 Coverage
  2. API Protection
  3. Access Control
  4. File Upload Control
  5. Detection of Unprotected Web Applications
  6. Penalty Box for Attackers
  7. Bot Protection
  8. DoS Protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does WAAS control access to protected applications?

A

Using Geo-based, IP-based, or HTTP Header-based user defined restrictions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the amount of time when a ban is enforced n of IPs that have triggered its protections in order to slow down vulnerability scanners and other attackers probing the application?

A

5 minutes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does Defender do in case it encounters encrypted sessions that require WAAS inspection?

A

Defender decrypts the traffic, examines the content, and then re-encrypts it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the different WAAS Actions?

A
  • Alert
    • The request is passed to the protected application and an audit is generated for visibility
  • Prevent
    • The request is denied from reaching the protected application, an audit is generated, and WAAS responds with an HTML page indicating the request was blocked.
  • Ban (3)
    • A ban can be applied on either IP or Prisma Session IDs
    • All requests originating from the same IP/Prisma Session to the protected application are denied for the configured time period (the default is five minutes) following the last detected attack
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does Prisma Cloud pushes policies to all resources to which they apply?

A

Whenever new policies are created or existing
policies are updated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How is WAAS enabled?

A

By adding a new WAAS rule.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does WAAS protect containerized web applications?

A

Prisma Cloud creates a firewall instance for each container instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does WAAS protect non-containerized web applications?

A

Prisma Cloud creates a firewall for each host specified in the configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly