Courseiva

CCSP Cloud Application Security Practice Question

Which TWO of the following are secure coding practices that help prevent injection attacks?

⚠ Common exam trap

ISC2 often tests the misconception that stored procedures are inherently safe against injection, but the trap is that stored procedures can still be vulnerable if they dynamically construct SQL strings using concatenated input, so parameterization must be applied inside the procedure as well.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using parameterized queries for database calls

Option B is correct because parameterized queries (prepared statements) separate SQL code from user-supplied data, so the database engine treats input as data rather than executable SQL, which neutralizes SQL injection. Option D is correct because validating and sanitizing all user inputs enforces expected formats and strips or escapes dangerous characters, reducing the attack surface for SQL, command, and other injection attacks. Option A is incorrect because printing stack traces in production leaks internal details such as file paths, query fragments, and framework versions that aid attackers, and it does nothing to prevent injection. Option C is incorrect because stored procedures are not inherently safe—if they build dynamic SQL by concatenating user input, they remain vulnerable to injection, so they are not a guaranteed secure coding practice. Option E is incorrect because storing passwords in plaintext is a severe confidentiality failure that enables credential theft and has no bearing on preventing injection attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Printing stack traces in production error messages

    Why it's wrong here

    Stack traces reveal schema, query fragments and library versions to attackers, aiding injection exploitation rather than preventing it. It is tempting because verbose errors speed debugging in development, where detailed traces are acceptable, but production responses must return generic messages while logs retain detail.

  • ✓

    Using parameterized queries for database calls

    Why this is correct

    Parameterised queries separate SQL code from user-supplied data, so the database engine treats input strictly as values rather than executable statements. This structurally prevents injection by ensuring untrusted data cannot alter query logic, directly satisfying the stem's requirement for a secure coding practise that mitigates injection attacks.

  • ✗

    Using stored procedures exclusively

    Why it's wrong here

    Stored procedures still execute dynamically constructed SQL when inputs are concatenated into statements, so injection remains possible. It is tempting because parameterised procedures reduce attack surface when written correctly, which suits legacy database-centric designs, but the practice itself is not inherently safe.

  • ✓

    Validating and sanitizing all user inputs

    Why this is correct

    Sanitising and validating user input strips or neutralises the metacharacters that injection payloads rely on, so untrusted data cannot alter the structure of a SQL, LDAP or OS command. This directly satisfies the stem's requirement for secure coding practices that prevent injection attacks.

  • ✗

    Storing user passwords in plaintext

    Why it's wrong here

    Plaintext password storage permits credential theft and reuse, doing nothing to stop injection. It is tempting because it avoids hashing overhead and simplifies recovery, which suits throwaway test fixtures, but production authentication requires salted adaptive hashing such as bcrypt or Argon2.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.