A company wants to enable WAF on their Application Gateway.After enabling WAF in Detection mode, they notice malicious requests are still reaching the backend.What should they do to block these requests?