A security analyst reviews a web application that accepts user-supplied data to generate PDF reports. The application uses a legacy library that directly inserts user input into SQL queries and also includes user input in the PDF generation without sanitization. Which is the most effective countermeasure?
Parameterised queries send SQL structure separately from user-supplied values, eliminating injection, while output encoding neutralises injected markup in the generated PDF. Together they address both the database and PDF generation flaws in the legacy library.
Why this answer
The application has two distinct vulnerabilities: SQL injection (from direct insertion of user input into SQL queries) and likely cross-site scripting or PDF injection (from unsanitized user input in PDF generation). Parameterized queries prevent SQL injection by separating code from data, while output encoding neutralizes malicious content before it is rendered in the PDF. Together, these address the root causes of both flaws, making A the most effective countermeasure.
Exam trap
CAS-005 often tests the misconception that a WAF is a sufficient countermeasure for injection flaws, when in fact it is only a compensating control and does not fix the root cause.
How to eliminate wrong answers
Option B is wrong because HTTPS and HSTS only protect data in transit, not the application-layer injection flaws described. Option C is wrong because a WAF is a compensating control that blocks known attack patterns but does not fix the underlying vulnerability; it can be bypassed and does not address the root cause. Option D is wrong because a SIEM provides logging and monitoring, which aids detection and response but does not prevent exploitation.