CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A development team wants to prevent SQL injection attacks against a customer-facing web application without altering the application's business logic. Which of the following is the MOST effective mitigation to implement in the application's database access layer?

  1. AEnforcing complex password policies for database accounts
  2. BUsing parameterized queries (prepared statements)
  3. CImplementing rate limiting on the login page
  4. DEncrypting all data at rest in the database
Show answer & explanation

Correct answer: B. Using parameterized queries (prepared statements)

Parameterized queries (prepared statements) separate SQL code from user-supplied data, ensuring input is always treated as data and never executed as part of the SQL command. This directly addresses the root cause of SQL injection, unlike password policies, encryption at rest, or rate limiting, which do not prevent malicious input from being interpreted as code.

Why the other options are wrong

  • A. Password complexity protects against credential attacks but does not stop malicious input from being executed as SQL code.
  • C. Rate limiting slows brute-force login attempts but does not address how the application processes SQL input.
  • D. Encryption at rest protects stored data from theft but does nothing to prevent injected SQL commands from executing.

Parameterized Queries

A secure coding technique that uses precompiled SQL statements with placeholders for user input, preventing the input from being interpreted as executable SQL code.

  • Also called prepared statements
  • Separates SQL logic from data
  • Primary defense against SQL injection, along with input validation and stored procedures

Memory trick: Parameterized queries build a fence: data stays data, code stays code.

More Threats, Vulnerabilities, and Mitigations questions