CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A developer modifies a web form's server-side code so that any submitted username field is checked against an approved allow-list of alphanumeric characters and rejected if it contains anything else before the value is processed further. Which secure coding practice is being applied?
- AOutput encoding
- BInput validation
- CParameterized queries
- DException handling
Show answer & explanationAnswer & explanation
Correct answer: B. Input validation
Input validation checks and restricts submitted data against expected formats or allow-lists before it is used, preventing malformed or malicious input from reaching application logic.
Why the other options are wrong
- A. Output encoding transforms data before it is rendered to a browser, not before processing input.
- C. Parameterized queries separate SQL code from data at the database layer, unrelated to form-level checks.
- D. Exception handling manages runtime errors, not input filtering.
Input Validation
Verifying that user-supplied data conforms to expected format, type, length, or character set before it is processed.
- Allow-listing is stronger than deny-listing
- Prevents injection, buffer overflow, and malformed data issues
- Should be enforced server-side, not just client-side
Memory trick: Validate in, Encode out, Parameterize queries, Handle errors gracefully.