SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A web application developer is designing a new e-commerce platform. To protect against SQL injection attacks, the developer must ensure that user-supplied input to database queries is handled securely. Which of the following is the most effective defense against SQL injection?

  1. AUsing prepared statements with parameterized queries.
  2. BRestricting database user permissions to only necessary tables.
  3. CImplementing client-side input validation using JavaScript.
  4. DEncoding all special characters in user input before storing them.
Show answer & explanation

Correct answer: A. Using prepared statements with parameterized queries.

Prepared statements with parameterized queries separate the SQL code from the user-supplied data, ensuring that user input is treated as data and not as executable code. This is the most robust defense against SQL injection.

Why the other options are wrong

  • B. Restricting permissions is a good security practice but doesn't prevent the injection itself, only limits its potential impact.
  • C. Client-side validation can be bypassed and should never be the sole defense.
  • D. Encoding can help but is not as foolproof as parameterized queries and might not cover all attack vectors.

SQL Injection Prevention

Techniques used to prevent malicious SQL code from being inserted into data-driven input fields, thereby altering or compromising SQL queries.

  • Parameterized queries are the primary defense.
  • Input validation (server-side) is crucial.
  • Least privilege for database accounts.

Memory trick: To stop SQLi, build a strong wall between data and commands.

More Systems and Application Security questions