CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A web application log shows the following request submitted to a login form: `POST /login.php HTTP/1.1` `username=admin' OR '1'='1&password=anything` Which secure coding practice would have most effectively prevented this attack from succeeding?
- AImplementing HTTPS with TLS 1.3 encryption
- BEnforcing strong password complexity requirements
- CUsing parameterized queries (prepared statements) for database access
- DAdding a CAPTCHA to the login form
Show answer & explanationAnswer & explanation
Correct answer: C. Using parameterized queries (prepared statements) for database access
The request shown is a classic SQL injection attempt exploiting string concatenation in a query. Parameterized queries (prepared statements) treat user input strictly as data, not executable SQL, preventing this class of injection regardless of the input content.
Why the other options are wrong
- A. TLS encrypts data in transit but does nothing to prevent injection at the application layer.
- B. Password complexity has no bearing on SQL injection, which bypasses the password check entirely.
- D. CAPTCHA prevents automated bot submissions but does not stop a manually crafted injection payload.
Parameterized Queries (Prepared Statements)
A secure coding technique that separates SQL code from user-supplied data, preventing SQL injection by treating input strictly as literal values.
- Prevents classic injection like ' OR '1'='1
- Also mitigate second-order injection risks
- Should be combined with input validation and least-privilege DB accounts
Memory trick: Parameters put the input in a locked box, not the query itself.