GCIH Web App Injection Attacks Practice Question
An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?
⚠ Common exam trap
Candidates often confuse input sanitization or escaping with parameterized queries, assuming that stripping dangerous characters like quotes provides complete protection against advanced SQL injection variants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Refactor database queries to use prepared statements with bound parameters via the application data access layer.
Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine treats input exclusively as data rather than executable code. Implementing parameterized queries globally stops SQL injection by neutralizing untrusted input regardless of characters appended by attackers, making it the definitive defense for database interaction security in incident response hardening.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement client-side JavaScript regex validation to strip SQL keywords from input parameters before transmission.
Why it's wrong here
Client-side validation offers zero security against determined attackers who bypass browser controls completely using intercepting proxies like Burp Suite. Attackers can submit raw HTTP requests directly to the application server, making client-side checks entirely ineffective for preventing server-side database injection attacks.
- ✗
Wrap all user inputs inside custom string-escaping functions designed to neutralize single quotes and semicolons.
Why it's wrong here
Manual escaping routines are notoriously fragile and frequently fail when facing complex character encodings, second-order injections, or database-specific nuances. Modern database drivers and frameworks provide robust built-in parameterization mechanisms that completely eliminate the human error inherent in custom escaping functions.
- ✓
Refactor database queries to use prepared statements with bound parameters via the application data access layer.
Why this is correct
Prepared statements separate code and data completely at the database driver level. When parameters are bound correctly, any user-supplied string like a UNION query is treated strictly as literal literal data values, neutralizing injection attempts and protecting backend data assets permanently.
- ✗
Deploy a traditional network firewall configured with signature rules to block incoming HTTP GET requests containing UNION.
Why it's wrong here
Network firewalls struggle with web application attacks because traffic is often encrypted via HTTPS, hiding the payload from inspection. Attackers can also easily evade simple signature rules using URL encoding, case manipulation, or chunked transfer coding to bypass perimeter defenses entirely.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.