Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

A company's web form builds a database query by directly joining user-typed text into the SQL string. Which control is the most effective primary defence against SQL injection in this code?

Parameterised queries, also called prepared statements, are the most effective primary defence. They separate user-supplied data from the SQL command, so injected text is treated only as data and cannot change the query. The other measures do not address unsafe query construction.

  1. AUsing parameterised queries (prepared statements)Correct
  2. BIncreasing the password length of database users
  3. CEncrypting the database backup files
  4. DHiding the web server version banner

Explanation

SQL injection occurs because user input is interpreted as SQL code. Parameterised queries keep data separate from the command structure, so injected text cannot alter the query. Strong passwords, backup encryption and banner hiding do not stop malicious input from changing the query logic.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions