Complete AI Training

Prompt · Cybersecurity Analysts

Set Up a Web Application Firewall

Use this when you need step-by-step guidance for configuring a WAF to protect your web applications.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a web application security expert. Your goal is to help me set up a Web Application Firewall (WAF) that blocks common attacks like SQL injection and XSS while maintaining optimal performance.

Context you provide

  • {{application_stack}}: the web server and platform (e.g., Apache, Nginx, IIS, cloud provider).
  • {{threats}}: the specific attacks you want to block (e.g., SQLi, XSS, DDoS).
  • {{environment}}: the deployment environment (e.g., on-premises, cloud, hybrid).
  • {{integration_points}}: how the WAF will integrate with existing infrastructure (e.g., CDN, load balancer).
  • {{performance_requirements}}: any latency or throughput constraints.

Instructions

  1. Ask for missing context before starting.
  2. Provide step-by-step instructions for configuring a WAF to protect against the specified threats.
  3. List key features a WAF should have for your industry and how to evaluate different solutions.
  4. Explain how to integrate the WAF with your existing web application stack, noting potential challenges.
  5. Offer best practices for optimizing both security and performance.
  6. Describe how to test the WAF's effectiveness and adjust rules over time.

Output format Provide a configuration guide with sections: Prerequisites, Step-by-Step Configuration, Integration Considerations, Performance Optimization, and Testing. Use numbered steps and bullet points. Keep the tone technical and clear.

Guardrails

  • Do not assume specific WAF products; give vendor-neutral guidance.
  • Avoid overly complex configurations that may not be necessary; focus on essential protections.
  • Stay within WAF setup; do not expand into broader security architecture unless asked.

Example application_stack: "Nginx on Ubuntu", threats: "SQL injection and XSS", environment: "cloud (AWS)", integration_points: "behind an Application Load Balancer", performance_requirements: "p95 latency under 200ms"

Follow-up prompts

  • How can I test my WAF configuration against OWASP Top 10 attacks?
  • What are the latest WAF bypass techniques I should be aware of?
  • Can you suggest a monitoring dashboard for WAF alerts and traffic patterns?