CCSP Cloud Application Security Practice Question
Exhibit
Refer to the exhibit. ``` [ERROR] 2025-03-01 12:34:56,789 - myapp - CRITICAL - SQL Injection detected on endpoint /api/login Input: ' OR '1'='1 ```
Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?
⚠ Common exam trap
ISC2 often tests the distinction between network-layer controls (like encryption) and application-layer controls (like input validation), and the trap here is that candidates confuse encryption of the connection with prevention of injection, thinking encrypted traffic cannot carry malicious payloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use parameterized SQL queries
SQL injection attacks exploit unsanitized user input that is concatenated into SQL queries. Parameterized queries (also known as prepared statements) separate SQL logic from data by using placeholders, ensuring that user input is always treated as data, not executable code. This prevents an attacker from injecting malicious SQL commands, regardless of the input content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the database connection
Why it's wrong here
Transport encryption protects data in transit from interception; it does not parse or sanitise SQL syntax, so injected statements still execute. Parameterised queries or input validation address the injection itself. Encryption is tempting because it hardens database traffic, and would be correct where confidentiality of credentials or data on the wire is the requirement.
- ✗
Implement rate limiting on the login endpoint
Why it's wrong here
Rate limiting throttles request frequency against the login endpoint, but the injected SQL still reaches the database and executes. It is the right control against brute-force or credential-stuffing attempts, whereas parameterised queries or input validation stop injection itself.
- ✗
Enforce strong password policies
Why it's wrong here
Password strength governs authentication, not query construction, so a valid session can still submit malicious SQL. Parameterised queries or input sanitisation prevent injection. Strong password policies are tempting because they harden access control, and would be correct where credential guessing or brute-force against accounts is the threat.
- ✓
Use parameterized SQL queries
Why this is correct
Parameterised queries bind user input as data rather than concatenating it into SQL text, so injected syntax never becomes executable code. This eliminates the injection vector at source, which no signature or input-filtering control achieves as reliably.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.