Courseiva

200-901 Application Deployment and Security Practice Question

A developer is writing a web application and needs to prevent SQL injection attacks. Which coding practice is most effective?

⚠ Common exam trap

200-901 often tests the difference between input validation and parameterization — candidates pick regex validation or escaping because they sound secure, but only parameterized queries eliminate the code/data mixing that enables SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use parameterized queries with prepared statements

Parameterized queries with prepared statements separate SQL code from user-supplied data, so the database treats input as data rather than executable SQL. This prevents attackers from injecting SQL syntax regardless of the input's content. It is the most robust and recommended defense against SQL injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Validate input with regex to allow only alphanumeric characters

    Why it's wrong here

    Regex allow-listing rejects legitimate values such as names with apostrophes or hyphens, and any field not matching the pattern still reaches the query unparameterised. It is tempting because input validation is a recognised control, and it would be correct for constraining a known-format field, but it cannot substitute for parameterised queries.

  • ✓

    Use parameterized queries with prepared statements

    Why this is correct

    Parameterised queries send SQL code and user-supplied values separately, so input is bound as data rather than parsed as executable SQL. This structurally prevents injection, unlike escaping or validation, which can be bypassed by crafted payloads.

  • ✗

    Use stored procedures exclusively

    Why it's wrong here

    Stored procedures still concatenate parameters into dynamic SQL when written that way, so injection remains possible; the protection comes from parameterisation, not from the procedure itself. It is tempting because procedures centralise and restrict database access, and would be correct alongside bound parameters, but exclusivity alone does not prevent injection.

  • ✗

    Escape all user input with htmlspecialchars

    Why it's wrong here

    htmlspecialchars encodes characters for HTML output, so it neutralises XSS rather than SQL syntax; the database driver still receives injectable input. It is tempting because escaping is a genuine defence, and it would be correct when rendering user data into a web page, but it does not parameterise SQL statements.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.