Courseiva
mediumMultiple Choice

SSCP Practice Question: A web application processes user-supplied data in…

A web application processes user-supplied data in SQL queries. Which practice best prevents SQL injection?

⚠ Common exam trap

Candidates often believe stored procedures are inherently safe against SQL injection. However, stored procedures only prevent injection if they do not construct dynamic SQL within the procedure body using concatenated user input. Parameterized queries (or prepared statements) are the definitive protection because they separate SQL logic from data entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Parameterized queries

Parameterized queries (also known as prepared statements) separate SQL logic from user data by using placeholders (e.g., `?` in MySQLi or `:name` in PDO). The database engine treats the user input strictly as data, never as executable SQL code, which inherently prevents SQL injection regardless of the input content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Parameterized queries

    Why this is correct

    Parameterised queries separate SQL code from user-supplied values by sending them as bound parameters, so input is never interpreted as executable SQL syntax. This neutralises injection regardless of the characters supplied, satisfying the requirement to prevent SQL injection in the application's queries.

  • ✗

    Escaping all user input

    Why it's wrong here

    Escaping input is error-prone and context-dependent; it fails where queries are built by string concatenation across dynamic fragments. Parameterised queries, which send SQL and data on separate protocol paths, are the correct control. Escaping is tempting because it addresses the immediate symptom in simple cases, but it cannot guarantee safety across all database dialects and encodings.

  • ✗

    Using stored procedures exclusively

    Why it's wrong here

    Stored procedures still execute dynamic SQL if they concatenate parameters, so injection remains possible. Parameterised queries, which send data separately from the SQL text, prevent it. Stored procedures would be the right choice for centralising and reusing database logic across applications.

  • ✗

    Input length validation

    Why it's wrong here

    Length validation constrains input size but does not stop crafted payloads within that length altering query structure. Parameterised queries bind user data as values, never as SQL syntax. Length validation would be the right choice for limiting buffer or field overflow risks.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.