CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy

A developer modifies a web form's server-side code so that any submitted username field is checked against an approved allow-list of alphanumeric characters and rejected if it contains anything else before the value is processed further. Which secure coding practice is being applied?

  1. AOutput encoding
  2. BInput validation
  3. CParameterized queries
  4. DException handling
Show answer & explanation

Correct answer: B. Input validation

Input validation checks and restricts submitted data against expected formats or allow-lists before it is used, preventing malformed or malicious input from reaching application logic.

Why the other options are wrong

  • A. Output encoding transforms data before it is rendered to a browser, not before processing input.
  • C. Parameterized queries separate SQL code from data at the database layer, unrelated to form-level checks.
  • D. Exception handling manages runtime errors, not input filtering.

Input Validation

Verifying that user-supplied data conforms to expected format, type, length, or character set before it is processed.

  • Allow-listing is stronger than deny-listing
  • Prevents injection, buffer overflow, and malformed data issues
  • Should be enforced server-side, not just client-side

Memory trick: Validate in, Encode out, Parameterize queries, Handle errors gracefully.

More Vulnerability Management questions