Courseiva
mediumMultiple Choice

CISA Practice Question: A financial institution recently experienced a…

A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?

⚠ Common exam trap

CISA often tests the misconception that a WAF or client-side validation provides sufficient protection — candidates must recognize that only server-side validation and parameterized queries address the root cause of SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client-side input validation is insufficient and server-side validation is missing.

The breach occurred because input validation was performed only on the client side using JavaScript, which an attacker can trivially bypass by disabling JavaScript, intercepting requests with a proxy, or crafting raw HTTP requests. Without server-side validation, malicious SQL payloads reach the database directly. The WAF logs showing no SQL injection detections further confirm the attack bypassed client-side controls and the WAF's signature set, but the root cause is the absence of server-side validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client-side input validation is insufficient and server-side validation is missing.

    Why this is correct

    JavaScript validation executes in the browser, so an attacker can bypass it entirely and submit crafted SQL directly to the server. With no server-side validation, the injection reached the database. This weakness directly enabled the breach, unlike the WAF, which logged blocked XSS attempts.

  • ✗

    The use of a shared DBA database account violates the principle of least privilege.

    Why it's wrong here

    Shared DBA credentials widen blast radius after compromise but did not enable the injection itself; the WAF saw no SQLi because client-side JavaScript validation is bypassable, so malicious input reached the database directly. Least-privilege database accounts are the right control when auditing privilege escalation or lateral movement risk.

  • ✗

    The WAF is misconfigured to detect only XSS attacks but not SQL injection.

    Why it's wrong here

    The logs show the WAF blocked XSS but recorded no SQL injection attempts, so detection was not disabled for that class. Misconfiguration is tempting because WAFs can be tuned per signature category, and that would be the fault if SQL rules were disabled — but here the payloads simply bypassed detection.

  • ✗

    The application server is not patched against known SQL injection vulnerabilities.

    Why it's wrong here

    SQL injection arises from unsafe query construction in the application code, not from unpatched server software; the server is not the injection point. Patching is tempting because missing patches cause many exploits, and it would be correct if the vulnerability were a known flaw in the server platform itself.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.