Courseiva

GCIH Web App Injection Attacks Practice Question

An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)

⚠ Common exam trap

Candidates often include 'WAF' or 'encryption'. While helpful, they are not the primary defenses against SQLi; parameterized queries and input validation are the fundamental, code-level requirements for prevention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing parameterized queries or prepared statements for all database interactions

Effective mitigation of SQL injection requires separating user-supplied data from executable query statements. Parameterized queries enforce strict data typing and prevent interpreters from executing user input as code, while robust input validation adds a crucial defense-in-depth layer by rejecting malformed payloads before database interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing parameterized queries or prepared statements for all database interactions

    Why this is correct

    Parameterised queries and prepared statements separate SQL code from user-supplied data, so input is bound as values rather than concatenated into statements. The database never interprets injected text as executable SQL, satisfying the primary defence requirement against SQL injection.

  • ✗

    Enabling client-side JavaScript validation to strip out single quotes and semicolons

    Why it's wrong here

    Relying on client-side input validation provides zero security assurance because attackers can easily bypass browser restrictions using intercepting proxies like Burp Suite. Security controls must always be enforced on the server side to protect backend assets.

  • ✓

    Applying robust input validation and whitelisting against expected parameter formats

    Why this is correct

    Input validation with whitelisting rejects malformed or unexpected parameter values before they reach the database, preventing attacker-supplied SQL syntax from being interpreted. It satisfies the primary defence requirement by constraining input to expected formats at the application boundary.

  • ✗

    Relying exclusively on Web Application Firewall signature blocking rules

    Why it's wrong here

    Signature rules only match known attack patterns, so they miss novel or obfuscated injection payloads that parameterised queries would neutralise at the database layer. WAFs are tempting as a compensating control for legacy code that cannot be changed, where patching the application itself is not feasible.

  • ✗

    Encoding all database query outputs using HTML entity encoding before rendering

    Why it's wrong here

    HTML entity encoding protects the rendering context against cross-site scripting; it does not alter how the database parses SQL syntax, so injected statements still execute. Output encoding is the right control when untrusted data is reflected into HTML pages rather than passed to a query.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.