Maria wants to deploy a web application firewall that will stop new attacks against her organization. What should she do to make sure that her web application firewall rules are as current as possible?
Answer Options
Manually add new rules based on email updates.
Deploy rules based on the OWASP Top 10.
Subscribe to a threat feed and deploy rules based on the feed.
Subscribe to the vendor's managed WAF rule service.
Correct Answer: D
Explanation
Many vendors offer a managed service that provides rules that stop trending and new attacks. Maria can subscribe to the service, but needs to be aware that sometimes rules may cause outages or issues if they block legitimate traffic accidentally. Manually deploying rules is slow and requires careful crafting. The Open Worldwide Application Security Project (OWASP) Top 10 is a short list and it is not updated quickly. Threat feeds are useful as a way to write rules but will be less effective than a managed service in most cases due to the variety of attacks and new threats.