Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Database Management

A web application builds its SQL query by directly joining text typed by a user into the query string. An attacker enters input that alters the query and retrieves all customer records. Which control is the most effective primary defence against this attack?

Parameterised queries combined with input validation are the primary defence. They ensure user input is treated only as data and never as executable SQL, which stops injection. Backups, larger disks and indexes do not prevent unauthorised data retrieval.

  1. AUsing parameterised queries with input validationCorrect
  2. BIncreasing the size of the database server's disk
  3. CScheduling more frequent full backups
  4. DCreating additional indexes on customer tables

Explanation

The flaw is SQL injection, where untrusted input is interpreted as SQL code. Parameterised queries with validation keep input as data, not code. Backups, extra disk and indexes do not stop the attacker from reading data; backups only help recovery and indexes only speed retrieval.

Did you get it right without looking?

One question tells you little. A timed set on Database Management shows your real accuracy, how long you take and where you lose marks.

More Database Management questions