Courseiva

SSCP Systems and Application Security Practice Question

A security analyst is reviewing logs from a web application and notices numerous requests with the following pattern: GET /products?category=1' OR '1'='1. The analyst suspects a SQL injection attack. Which of the following is the MOST effective control to prevent this type of attack?

⚠ Common exam trap

The trap here is relying on input validation or a WAF as the primary defense, when they can be bypassed or may not cover all injection vectors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use parameterized queries (prepared statements) for all database access.

SQL injection occurs when user input is concatenated into SQL queries, allowing attackers to alter the query logic. Parameterized queries separate the query structure from the data, ensuring that input cannot change the intended SQL command. This is the most effective and reliable prevention method, as it addresses the root cause rather than relying on detection or input filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a web application firewall (WAF) to block SQL injection patterns.

    Why it's wrong here

    A WAF can provide an additional layer of defense, but it is not the most effective control because it relies on pattern matching and can be bypassed with obfuscation. It should be used as a compensating control, not as the primary mitigation for SQL injection.

  • ✓

    Use parameterized queries (prepared statements) for all database access.

    Why this is correct

    Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, effectively mitigating SQL injection regardless of the input's content. It is the most effective control for this vulnerability.

  • ✗

    Implement input validation to reject requests containing single quotes.

    Why it's wrong here

    While input validation can help, simply rejecting single quotes is not sufficient because attackers can use other techniques like encoding or alternative SQL syntax. It may also break legitimate requests that contain quotes. A more robust solution is needed to prevent SQL injection.

  • ✗

    Store the database in a read-only mode to prevent data modification.

    Why it's wrong here

    A read-only database would prevent data modification but not data disclosure. SQL injection can still be used to extract sensitive information via SELECT statements. This control does not address the root cause and would likely break application functionality.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.