Courseiva

GSEC Web Communication Security Practice Question

A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?

⚠ Common exam trap

Test-takers frequently confuse input validation or encoding with proper query parameterization, which is the definitive fix for SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use parameterized queries (prepared statements) for all database access.

SQL injection occurs when user input is improperly concatenated into SQL queries. Parameterized queries, also known as prepared statements, ensure that input is bound as parameters and never interpreted as SQL code. This eliminates the vulnerability entirely. While WAFs and input validation can help, they are not as reliable or comprehensive. Therefore, using parameterized queries is the most effective mitigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a Web Application Firewall (WAF) with SQL injection signatures.

    Why it's wrong here

    A WAF can block known SQL injection patterns, but it is a reactive measure that can be bypassed with obfuscation or new techniques. It does not fix the underlying vulnerability in the application code. While it adds a layer of defense, it should not be the primary mitigation. The most effective solution is to address the root cause by using parameterized queries.

  • ✗

    Implement strict input validation to allow only alphanumeric characters.

    Why it's wrong here

    Strict input validation can reduce the attack surface, but it is not foolproof and can break legitimate functionality if not carefully designed. Attackers can sometimes bypass validation using encoding or alternative characters. Moreover, it does not address the root cause if the application still concatenates input into SQL queries. Parameterized queries are a more robust solution.

  • ✗

    Encode all user input using HTML entity encoding before storing in the database.

    Why it's wrong here

    HTML entity encoding is used to prevent cross-site scripting (XSS) when outputting data to HTML contexts, not to prevent SQL injection. Applying it before database storage would not stop SQL injection because the database interprets encoded characters as part of the SQL syntax. It is the wrong layer of defense for this attack type.

  • ✓

    Use parameterized queries (prepared statements) for all database access.

    Why this is correct

    Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, regardless of the input's content. It is the most effective and fundamental mitigation against SQL injection, as it eliminates the vulnerability at the source rather than relying on pattern matching.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.