CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Database Management
A web application builds its SQL query by directly joining text typed by a user into the query string. An attacker enters input that alters the query and retrieves all customer records. Which control is the most effective primary defence against this attack?
Parameterised queries combined with input validation are the primary defence. They ensure user input is treated only as data and never as executable SQL, which stops injection. Backups, larger disks and indexes do not prevent unauthorised data retrieval.
- AUsing parameterised queries with input validationCorrect
- BIncreasing the size of the database server's disk
- CScheduling more frequent full backups
- DCreating additional indexes on customer tables
Explanation
The flaw is SQL injection, where untrusted input is interpreted as SQL code. Parameterised queries with validation keep input as data, not code. Backups, extra disk and indexes do not stop the attacker from reading data; backups only help recovery and indexes only speed retrieval.
Did you get it right without looking?
One question tells you little. A timed set on Database Management shows your real accuracy, how long you take and where you lose marks.
More Database Management questions
- A firm's database administrator runs a DELETE statement without a WHERE clause inside a transaction that has not been committed, then realis…
- A fintech company mines its big-data store of customer records to profile individual behaviour and sells the profiles to advertisers. The re…
- In an ER design for a listed company's compliance system, 'Dependent' (family members of an employee) has no key of its own and is identifie…
- In an Employee table, Emp_ID is the primary key, and columns are Dept_ID and Dept_Head, where Dept_ID determines Dept_Head. A company wants …
- A company's payment database transfers Rs 5,000 from Account A to Account B. The debit on A succeeds, but the system crashes before the cred…
- A bank's employee, while a transaction updating a customer's balance is still uncommitted, is shown by another session a balance value that …