CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A software development team is creating a new application that will interact with a database containing sensitive customer information. To prevent malicious code from being injected into the database via user input, which of the following practices should the developers prioritize?

  1. ARegularly backing up the database to an offsite location.
  2. BConfiguring the database to run with the highest possible privileges.
  3. CImplementing robust server-side input validation and parameterized queries.
  4. DEncrypting all data fields in the database at the column level.
Show answer & explanation

Correct answer: C. Implementing robust server-side input validation and parameterized queries.

Implementing robust server-side input validation ensures that only expected and safe data formats are processed. Parameterized queries, also known as prepared statements, separate SQL code from user input, effectively preventing SQL injection by treating all input as data, not executable code.

Why the other options are wrong

  • A. Backing up data is for disaster recovery, not prevention of injection attacks.
  • B. Running with high privileges increases the risk if an injection attack is successful, making it worse.
  • D. Column-level encryption protects data confidentiality but does not prevent malicious code injection.

Parameterized Queries

Parameterized queries (or prepared statements) are a method of executing SQL queries where the SQL code is defined separately from the data values, preventing SQL injection by treating all input as data rather than executable code.

  • Separates SQL logic from data.
  • Automatically escapes special characters.
  • Primary defense against SQL injection.

Memory trick: Guard the SQL gate with parameters.

More Data and Database Security questions