DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy
A developer is designing a RESTful API that will be consumed by both internal and external client applications. To protect against common web vulnerabilities, they need to implement measures to prevent attackers from injecting malicious scripts into the application's user interface via input fields. Which security best practice directly addresses this concern?
- AEncryption at Rest
- BMulti-Factor Authentication (MFA)
- CInput Validation and Sanitization
- DRate Limiting
Show answer & explanationAnswer & explanation
Correct answer: C. Input Validation and Sanitization
Input validation and sanitization are crucial for preventing injection attacks like Cross-Site Scripting (XSS). By validating input against expected formats and sanitizing it to remove or neutralize malicious characters, the application can prevent attackers from executing arbitrary code.
Why the other options are wrong
- A. Encryption at Rest protects data stored on disk, not against script injection vulnerabilities during input processing.
- B. Multi-Factor Authentication (MFA) enhances user login security, unrelated to preventing script injection via input fields.
- D. Rate Limiting protects against denial-of-service attacks, not script injection.
Input Validation and Sanitization
The process of checking user-supplied data to ensure it conforms to expected formats and removing or escaping potentially malicious characters to prevent injection attacks.
- Crucial for preventing Cross-Site Scripting (XSS) and SQL Injection.
- Validation ensures data is correct and complete.
- Sanitization cleans or escapes data to remove harmful content.
Memory trick: Verify and clean all incoming data.