A WAF operates by sitting between the client and the web server. It analyzes incoming traffic and blocks malicious requests based on predefined security rules. These rules can be customized to address specific threats, making WAF a flexible and essential tool for web application security.