ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityHard

A development team is implementing a new API for their microservices architecture. To prevent common web application attacks, they are focusing on validating all input received by the API. Which validation strategy is generally considered the most secure and robust?

  1. ABlacklisting known malicious characters or patterns.
  2. BWhitelisting acceptable characters, patterns, or data types.
  3. CUsing regular expressions to sanitize input after receipt.
  4. DRelying on client-side validation to filter out malicious input.
Show answer & explanation

Correct answer: B. Whitelisting acceptable characters, patterns, or data types.

Whitelisting is generally considered the most secure input validation strategy. Instead of trying to identify and block all possible malicious inputs (which is prone to bypasses), whitelisting explicitly defines what *is* allowed. Any input that does not conform to the whitelist is rejected, making it much harder for attackers to craft unexpected or malicious payloads.

Why the other options are wrong

  • A. Blacklisting is inherently insecure as it's difficult to anticipate all possible attack vectors, often leading to bypasses.
  • C. Sanitizing input is better than no validation, but it's a reactive measure. Whitelisting prevents invalid input from being processed at all. Also, regex can be complex and error-prone.
  • D. Client-side validation is easily bypassed by an attacker and should never be the sole method of input validation; server-side validation is mandatory.

Input Whitelisting

An input validation strategy that explicitly defines and allows only known-good, safe input values, characters, or patterns, rejecting everything else by default.

  • Positive security model (allow-by-default)
  • More secure than blacklisting
  • Harder to bypass, robust against unknown attacks

Memory trick: Whitelist your inputs, keep the bad ones out, no nasty surprises, no security doubt.

More Software Development Security questions