Courseiva

CEH Web Application and Injection Attacks Practice Question

Which TWO of the following attacks can be prevented by properly validating and sanitizing user input? (Select 2)

⚠ Common exam trap

CEH often tests the misconception that input validation stops all web attacks — candidates must recognize that CSRF, clickjacking, and MitM are session/transport-layer attacks immune to sanitization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

Option B (SQL injection) is correct because SQL injection occurs when untrusted user input is concatenated into SQL queries, and validating/sanitizing that input (or using parameterized queries/prepared statements) prevents attackers from injecting malicious SQL syntax. Option E (Cross-Site Scripting, XSS) is correct because XSS arises when user-supplied data is rendered into HTML/JavaScript without proper output encoding or input sanitization, so validating and sanitizing input stops script payloads from executing in victims' browsers. Option A (CSRF) is not prevented by input validation alone; it requires anti-CSRF tokens, SameSite cookies, or origin/referer checks, since the attack abuses a victim's authenticated session rather than malformed input. Option C (MitM) is a network-layer interception problem mitigated by TLS, certificate pinning, and secure protocols, not by input validation. Option D (Clickjacking) is prevented by frame-busting headers such as X-Frame-Options or Content-Security-Policy frame-ancestors, not by sanitizing user input.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-Site Request Forgery (CSRF)

    Why it's wrong here

    Cross-Site Request Forgery (CSRF) attacks exploit the trust a web application has in a user's browser, compelling the browser to send an unauthorized request to a trusted site. Input validation focuses on the legitimacy of the data itself, not the legitimacy of the request's origin or the user's intent. Therefore, proper prevention relies on implementing anti-CSRF tokens, which verify that the request originated from the legitimate application and not from an attacker's site, rather than scrutinizing the input data.

  • ✓

    SQL injection

    Why this is correct

    SQL injection attacks occur when an attacker inserts malicious SQL code into user input fields, which is then executed by the database. Proper input validation and sanitization are highly effective against this threat. Techniques such as using parameterized queries (prepared statements) or escaping special characters ensure that user-supplied data is treated strictly as data literals, preventing it from being interpreted as executable SQL commands and neutralizing the injection attempt.

  • ✗

    Man-in-the-Middle (MitM) attack

    Why it's wrong here

    A Man-in-the-Middle (MitM) attack involves an attacker intercepting and potentially altering communications between two parties without their knowledge. This type of attack operates primarily at the network or transport layer, focusing on compromising the confidentiality and integrity of data in transit. Input validation, which occurs at the application layer to scrutinize user-supplied data, cannot prevent an attacker from interposing themselves in the communication channel or from manipulating encrypted traffic if the underlying transport security (like TLS/SSL) is compromised.

  • ✗

    Clickjacking

    Why it's wrong here

    Clickjacking, or UI redressing, tricks users into clicking on a hidden, malicious element by overlaying a transparent iframe on a legitimate webpage. This attack manipulates the user interface and browser rendering behavior, rather than exploiting vulnerabilities related to data input or processing. Consequently, input validation is ineffective; defenses against clickjacking primarily involve implementing HTTP security headers such as `X-Frame-Options` or the `Content-Security-Policy` (CSP) `frame-ancestors` directive, which control how web pages can be embedded.

  • ✓

    Cross-Site Scripting (XSS)

    Why this is correct

    Cross-Site Scripting (XSS) attacks inject malicious client-side scripts into web pages, which are then executed in the victim's browser. This vulnerability arises when an application fails to properly validate, sanitize, or encode user-supplied input before rendering it back to the user. By rigorously sanitizing input to remove or neutralize executable script tags and encoding output to ensure user data is displayed as text rather than interpreted as active code, applications can effectively prevent XSS vulnerabilities.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.