200-901 Application Deployment and Security Practice Question
A developer is writing a web application and needs to prevent SQL injection attacks. Which coding practice is most effective?
⚠ Common exam trap
200-901 often tests the difference between input validation and parameterization — candidates pick regex validation or escaping because they sound secure, but only parameterized queries eliminate the code/data mixing that enables SQL injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use parameterized queries with prepared statements
Parameterized queries with prepared statements separate SQL code from user-supplied data, so the database treats input as data rather than executable SQL. This prevents attackers from injecting SQL syntax regardless of the input's content. It is the most robust and recommended defense against SQL injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Validate input with regex to allow only alphanumeric characters
Why it's wrong here
Regex allow-listing rejects legitimate values such as names with apostrophes or hyphens, and any field not matching the pattern still reaches the query unparameterised. It is tempting because input validation is a recognised control, and it would be correct for constraining a known-format field, but it cannot substitute for parameterised queries.
- ✓
Use parameterized queries with prepared statements
Why this is correct
Parameterised queries send SQL code and user-supplied values separately, so input is bound as data rather than parsed as executable SQL. This structurally prevents injection, unlike escaping or validation, which can be bypassed by crafted payloads.
- ✗
Use stored procedures exclusively
Why it's wrong here
Stored procedures still concatenate parameters into dynamic SQL when written that way, so injection remains possible; the protection comes from parameterisation, not from the procedure itself. It is tempting because procedures centralise and restrict database access, and would be correct alongside bound parameters, but exclusivity alone does not prevent injection.
- ✗
Escape all user input with htmlspecialchars
Why it's wrong here
htmlspecialchars encodes characters for HTML output, so it neutralises XSS rather than SQL syntax; the database driver still receives injectable input. It is tempting because escaping is a genuine defence, and it would be correct when rendering user data into a web page, but it does not parameterise SQL statements.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.