Courseiva
Web App Injection Attacks →mediumMultiple Choice

GCIH Web App Injection Attacks Practice Question

An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?

⚠ Common exam trap

Candidates often confuse input sanitization or escaping with parameterized queries, assuming that stripping dangerous characters like quotes provides complete protection against advanced SQL injection variants.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Refactor database queries to use prepared statements with bound parameters via the application data access layer.

Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine treats input exclusively as data rather than executable code. Implementing parameterized queries globally stops SQL injection by neutralizing untrusted input regardless of characters appended by attackers, making it the definitive defense for database interaction security in incident response hardening.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement client-side JavaScript regex validation to strip SQL keywords from input parameters before transmission.

    Why it's wrong here

    Client-side validation offers zero security against determined attackers who bypass browser controls completely using intercepting proxies like Burp Suite. Attackers can submit raw HTTP requests directly to the application server, making client-side checks entirely ineffective for preventing server-side database injection attacks.

  • ✗

    Wrap all user inputs inside custom string-escaping functions designed to neutralize single quotes and semicolons.

    Why it's wrong here

    Manual escaping routines are notoriously fragile and frequently fail when facing complex character encodings, second-order injections, or database-specific nuances. Modern database drivers and frameworks provide robust built-in parameterization mechanisms that completely eliminate the human error inherent in custom escaping functions.

  • ✓

    Refactor database queries to use prepared statements with bound parameters via the application data access layer.

    Why this is correct

    Prepared statements separate code and data completely at the database driver level. When parameters are bound correctly, any user-supplied string like a UNION query is treated strictly as literal literal data values, neutralizing injection attempts and protecting backend data assets permanently.

  • ✗

    Deploy a traditional network firewall configured with signature rules to block incoming HTTP GET requests containing UNION.

    Why it's wrong here

    Network firewalls struggle with web application attacks because traffic is often encrypted via HTTPS, hiding the payload from inspection. Attackers can also easily evade simple signature rules using URL encoding, case manipulation, or chunked transfer coding to bypass perimeter defenses entirely.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.