200-201 Security Concepts Practice Question
A company wants to protect its web application from injection attacks by ensuring that user-supplied input is not interpreted as code by the backend database. Which control should be implemented?
⚠ Common exam trap
The trap here is choosing a WAF or input validation as the primary fix, when the root cause is the lack of separation between code and data in the query.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Parameterized queries
Parameterized queries ensure that user input is passed as data and never concatenated into the SQL statement, so the database cannot interpret it as code. This is the most effective and fundamental defense against SQL injection, unlike input validation, output encoding, or a WAF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web application firewall
Why it's wrong here
A web application firewall can block known injection patterns, but it is a compensating control that may be bypassed with obfuscation. It does not fundamentally separate data from code, so it is not the primary control to ensure input is not interpreted as code by the database.
- ✗
Output encoding
Why it's wrong here
Output encoding transforms special characters before rendering data in a browser, which prevents cross-site scripting. It does not address SQL injection because the data is still sent to the database as part of a query, so it fails to stop the database from interpreting input as code.
- ✓
Parameterized queries
Why this is correct
Parameterized queries, also called prepared statements, separate SQL code from data by sending the query structure and parameters separately. The database treats parameters as data, not executable code, which prevents SQL injection even if the input contains malicious characters. This directly meets the requirement.
- ✗
Input validation
Why it's wrong here
Input validation checks that user input meets expected format and range, but it alone does not prevent SQL injection if the input is still concatenated into queries. It is a useful defense-in-depth measure, yet it does not separate data from code, which is the core requirement to stop injection.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.