GCIH Web App Injection Attacks Practice Question
An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)
⚠ Common exam trap
Candidates often include 'WAF' or 'encryption'. While helpful, they are not the primary defenses against SQLi; parameterized queries and input validation are the fundamental, code-level requirements for prevention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing parameterized queries or prepared statements for all database interactions
Effective mitigation of SQL injection requires separating user-supplied data from executable query statements. Parameterized queries enforce strict data typing and prevent interpreters from executing user input as code, while robust input validation adds a crucial defense-in-depth layer by rejecting malformed payloads before database interaction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing parameterized queries or prepared statements for all database interactions
Why this is correct
Parameterised queries and prepared statements separate SQL code from user-supplied data, so input is bound as values rather than concatenated into statements. The database never interprets injected text as executable SQL, satisfying the primary defence requirement against SQL injection.
- ✗
Enabling client-side JavaScript validation to strip out single quotes and semicolons
Why it's wrong here
Relying on client-side input validation provides zero security assurance because attackers can easily bypass browser restrictions using intercepting proxies like Burp Suite. Security controls must always be enforced on the server side to protect backend assets.
- ✓
Applying robust input validation and whitelisting against expected parameter formats
Why this is correct
Input validation with whitelisting rejects malformed or unexpected parameter values before they reach the database, preventing attacker-supplied SQL syntax from being interpreted. It satisfies the primary defence requirement by constraining input to expected formats at the application boundary.
- ✗
Relying exclusively on Web Application Firewall signature blocking rules
Why it's wrong here
Signature rules only match known attack patterns, so they miss novel or obfuscated injection payloads that parameterised queries would neutralise at the database layer. WAFs are tempting as a compensating control for legacy code that cannot be changed, where patching the application itself is not feasible.
- ✗
Encoding all database query outputs using HTML entity encoding before rendering
Why it's wrong here
HTML entity encoding protects the rendering context against cross-site scripting; it does not alter how the database parses SQL syntax, so injected statements still execute. Output encoding is the right control when untrusted data is reflected into HTML pages rather than passed to a query.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.