WAF Wednesdays Big Fat Quiz of the Financial Year

 
Welcome to the WAF Wednesdays Big Fat Quiz of the Financial Year.
 
To celebrate the return to zero here is a test of your Barracuda Application Security knowledge.
 
To make the quiz fair, it is open for all until the 11th of March (international date line). Everybody gets one attempt but if you leave now this will count. The questions and answers are randomised and you get 1 minute to answer before the quiz automatically moves on.
 
There is a prize for the individual who comes first.
 
Press next to start the clock... And good Luck!
 
Welcome to the WAF Wednesdays Big Fat Quiz of the Financial Year.
 
To celebrate the return to zero here is a test of your Barracuda Application Security knowledge.
 
To make the quiz fair, it is open for all until the 11th of March (international date line). Everybody gets one attempt but if you leave now this will count. The questions and answers are randomised and you get 1 minute to answer before the quiz automatically moves on.
 
There is a prize for the individual who comes first.
 
Press next to start the clock... And good Luck!
Which of these features is currently only available on Barracuda WAF appliances?
Identity Access Management (IAM)
Vulnerability Remediation Service (VRS)
Advanced Threat Protection (ATP)
Log Export
Central Management
Which of these Public Clouds is not currently supported by Barracuda WAF appliances?
Google Cloud Platform (GCP)
Oracle Cloud Infrastructure (OCI)
Microsoft Azure
Amazon Web Services (AWS)
Huawei Mobile Cloud (HMC)
Which of these hyperconverged platforms is fully supported by Barracuda WAF appliances?
Cisco HyperFlex
Nutanix AVH
Dell VxRail
Huawei FusionCube
HPE SimpliVity
Which Marketplaces can currently be used to purchase Barracuda WAF-as-a-Service?
Ingram Cloud Marketplace
Google Cloud Marketplace
Azure Marketplace
AWS Marketplace
Oracle Cloud Marketplace
What is the main advantage of Barracuda WAF-as-a-Service over Barracuda WAF
Can be deployed in the customers own infrastructure wherever that might be
Can provide comprehensive protection for both modern API and traditional web traffic
Can load-balance incoming traffic between multiple backend application servers
Integrates with Barracuda Vulnerability Remediation Service to enable Continuous Integration and Continuous Delivery (CI/CD) workflows
Simple flexibility that is Massively scalable and globally available with built-in Full-spectrum DDoS Protection
Which of these CAP features is not currently available in Barracuda WAF-as-a-Service?
DDoS Protection
Client-Side Protection
API Protection
Identity and Access Control
Active Threat Intelligence
How long does it take to onboard the average application in WAF-as-a-Service?
An Minute
An hour
A day
A week
A month
Barracuda WAF-as-a-Service can now be deployed in which environment?
Quays
Spades
Buckets
Containers
Tubs
A Customer starts talking about Compliance. What should you do?
Run. Barracudas AppSec products do not have any compliance certifications
Tell them about WAF-as-a-Service and point them to the Barracuda Trust Center for more information about its PCI-DSS certification
Tell them about WAF-as-a-Service and point them to the Barracuda Trust Center for more information about its SOC2 Type2 certification
Tell them about the feature set included in Barracuda WAF and WAF-as-a-Service that are available to help them deploy the products so they can meet their compliance obligations
Tell them that all Barracuda products are ISO certified and point them to the Barracuda Trust Center for more information
What are the ABCs of Application Security
Apps, Bots, and Client Protection
Adventures, Bots, and Cloud Protection
APIs, Bells and Cloud Protection
Apps, Bells, and Client Protection
APIs, Bots, and Client Protection
A customer has no knowledge about application security at all, they need some help, you:
Position Barracuda Professional Services
Sell them WAF
Ask Pre-sales to do it
Position a partner with Application Security knowledge
Sell them WAF-as-a-Service
An API is?
The sound of an engineer sneezing
A way to directly interact with the business logic in an application
A vulnerability
A hacking technique
The sound of sales yawning
A Customer asks you about OWASP top 10 and if the Barracuda solution protects against that, You:
Panic and call a pre-sales engineer
Tell the customer that we indeed protect against OWASP top 10
While putting on your most confident smile, you tell the customer that we protect against so much more than the OWASP top 10. Have they thought about bots?
Customer in health care is worried about personal data being visible in the WAF-as-a-Service. How can we mitigate their concerns:
Sell them WAF
Tell them to not add the websites that have secure information
Tell them about the log masking feature
Tell them about custom containers and local logging
Close the call and run
Retail customer wants fast delivery of their applications and asks for a CDN, can we help them?
Yes! Of course we can supply a CDN
No, unfortunately that's not a feature for us right now
During a demo, a customer says they need to keep the data on-premise, can we still sell WAF-as-a-Service?
Yes
No
What is a good reason to buy WAF-as-a-Service?
Customer needs to protect an old website
Customer needs to protect a modern website
Customer does not have much WAF experience
Customer does not have time for administration
All of the above
What is a core differentiator for Barracuda WAF-as-a-Service?
Cheaper than competitors
More expensive than competitors
Ease of use
What are the big three topics of Application Security?
API Protection
Bot Protection
Client Side Protection
DDoS Protection
In the application security market, what else does Client-Side Protection get called?
Supply Chain Attack Protection
Skimming Protection
Page Integrity Protection
Magecart Protection
Magic Resource Integrity
What is the SKU for CAP 2.0?
BWFi1060a
BWFSi001a
CAP is not a product so it has no SKU
BASiCCV400a
BWFiCAW015a
What does CSP stand for in the context of CAP 2.0?
Client-Side Protection
Client-Side Policy
Client Security Policy
Content Security Policy
Client Server Process
Which of these are features of CAP 2.0?
DDoS Protection
Active Threat Intelligence
API Protection
Advanced Threat Protection
Client-Side Protection
What does CAP stand for?
Client Application Protection
Cloud Application Platform
Cloud Application Protection
Client Application Platform
What features are covered in the Advanced Threat Intelligence (ATI) dashboard?
Client-Side Protection (CSP)
API Protection
Auto-Configuration Engine (ACE)
Account Take-Over (ATO) Protection
Advanced Bot Protection (ABP)
Is the Active Threat Intelligence dashboard free to use for Barracuda WAF or WAF-as-a-Service customers?
No, the ABP add-on subscription is required in order to use ATI
Yes, a valid EU subscription for WAF or WAF-as-a-Service can use ATI
I want to buy a PlayStation 5, but they are all sold out 2 minutes after being released. This is the fault of:
Rampant Consumerism
DDoS
Ransomware
The Web Store
Bots
Bots are always malicious
Yes
No
Does a WAF protect against future vulnerabilities as well?
Yes
No
Approximately what portion of the internet consists of bots in 2022?
10%
20%
40%
60%
90%
What parts of the NIST Cybersecurity Framework does the WAF operate in?
Prevent
Detect
Respond
Recover
Identify
Distributed Denial of Service (DDoS) attacks are a specific type of automated bot attack. Which features can be used to protect against them?
Brute Force Protection
Honeypots
Bot Lists
Slow Client Prevention
Client Evaluation
Blocking an entire IP address for bad behaviour causes significant problems. How can Advanced Bot Protection (ABP) help?
Blocking bot spam will help prevent the IP address becoming deny-listed
Client Fingerprinting blocks an individual proxy
Client Fingerprinting blocks an individual client
Client Fingerprinting blocks an individual network
Proactive defence denying malicious bots will prevent an IP address getting denied
What additional features are also included with the Advanced Bot Protection (ABP) licence for WAF?
Auto-Configuration Engine (ACE)
Risk Scoring
Advanced Threat Intelligence (ATI)
Session Tacking
Google ReCAPTCHA
Does our WAF protect against LOG4J Vulnerabilities?
Yes
No
{"name":"WAF Wednesdays Big Fat Quiz of the Financial Year", "url":"https://www.quiz-maker.com/QPREVIEW","txt":"Welcome to the WAF Wednesdays Big Fat Quiz of the Financial Year.   To celebrate the return to zero here is a test of your Barracuda Application Security knowledge.   To make the quiz fair, it is open for all until the 11th of March (international date line). Everybody gets one attempt but if you leave now this will count. The questions and answers are randomised and you get 1 minute to answer before the quiz automatically moves on.   There is a prize for the individual who comes first.   Press next to start the clock... and good Luck!, Which of these features is currently only available on Barracuda WAF appliances?, Which of these Public Clouds is not currently supported by Barracuda WAF appliances?","img":"https://www.quiz-maker.com/3012/images/ogquiz.png"}
Make your own Survey
- it's free to start.