CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A web application log shows the following request submitted to a login form: `POST /login.php HTTP/1.1` `username=admin' OR '1'='1&password=anything` Which secure coding practice would have most effectively prevented this attack from succeeding?

  1. AImplementing HTTPS with TLS 1.3 encryption
  2. BEnforcing strong password complexity requirements
  3. CUsing parameterized queries (prepared statements) for database access
  4. DAdding a CAPTCHA to the login form
Show answer & explanation

Correct answer: C. Using parameterized queries (prepared statements) for database access

The request shown is a classic SQL injection attempt exploiting string concatenation in a query. Parameterized queries (prepared statements) treat user input strictly as data, not executable SQL, preventing this class of injection regardless of the input content.

Why the other options are wrong

  • A. TLS encrypts data in transit but does nothing to prevent injection at the application layer.
  • B. Password complexity has no bearing on SQL injection, which bypasses the password check entirely.
  • D. CAPTCHA prevents automated bot submissions but does not stop a manually crafted injection payload.

Parameterized Queries (Prepared Statements)

A secure coding technique that separates SQL code from user-supplied data, preventing SQL injection by treating input strictly as literal values.

  • Prevents classic injection like ' OR '1'='1
  • Also mitigate second-order injection risks
  • Should be combined with input validation and least-privilege DB accounts

Memory trick: Parameters put the input in a locked box, not the query itself.

More Vulnerability Management questions