Courseiva

CCSP Cloud Application Security Practice Question

Exhibit

Refer to the exhibit.

```
[ERROR] 2025-03-01 12:34:56,789 - myapp - CRITICAL - SQL Injection detected on endpoint /api/login
Input: ' OR '1'='1
```

Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?

⚠ Common exam trap

ISC2 often tests the distinction between network-layer controls (like encryption) and application-layer controls (like input validation), and the trap here is that candidates confuse encryption of the connection with prevention of injection, thinking encrypted traffic cannot carry malicious payloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use parameterized SQL queries

SQL injection attacks exploit unsanitized user input that is concatenated into SQL queries. Parameterized queries (also known as prepared statements) separate SQL logic from data by using placeholders, ensuring that user input is always treated as data, not executable code. This prevents an attacker from injecting malicious SQL commands, regardless of the input content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt the database connection

    Why it's wrong here

    Transport encryption protects data in transit from interception; it does not parse or sanitise SQL syntax, so injected statements still execute. Parameterised queries or input validation address the injection itself. Encryption is tempting because it hardens database traffic, and would be correct where confidentiality of credentials or data on the wire is the requirement.

  • ✗

    Implement rate limiting on the login endpoint

    Why it's wrong here

    Rate limiting throttles request frequency against the login endpoint, but the injected SQL still reaches the database and executes. It is the right control against brute-force or credential-stuffing attempts, whereas parameterised queries or input validation stop injection itself.

  • ✗

    Enforce strong password policies

    Why it's wrong here

    Password strength governs authentication, not query construction, so a valid session can still submit malicious SQL. Parameterised queries or input sanitisation prevent injection. Strong password policies are tempting because they harden access control, and would be correct where credential guessing or brute-force against accounts is the threat.

  • ✓

    Use parameterized SQL queries

    Why this is correct

    Parameterised queries bind user input as data rather than concatenating it into SQL text, so injected syntax never becomes executable code. This eliminates the injection vector at source, which no signature or input-filtering control achieves as reliably.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.