mediumMultiple Choice
SSCP Practice Question: A web application processes user-supplied data in…
A web application processes user-supplied data in SQL queries. Which practice best prevents SQL injection?
⚠ Common exam trap
Candidates often believe stored procedures are inherently safe against SQL injection. However, stored procedures only prevent injection if they do not construct dynamic SQL within the procedure body using concatenated user input. Parameterized queries (or prepared statements) are the definitive protection because they separate SQL logic from data entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Parameterized queries
Parameterized queries (also known as prepared statements) separate SQL logic from user data by using placeholders (e.g., `?` in MySQLi or `:name` in PDO). The database engine treats the user input strictly as data, never as executable SQL code, which inherently prevents SQL injection regardless of the input content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Parameterized queries
Why this is correct
Parameterised queries separate SQL code from user-supplied values by sending them as bound parameters, so input is never interpreted as executable SQL syntax. This neutralises injection regardless of the characters supplied, satisfying the requirement to prevent SQL injection in the application's queries.
- ✗
Escaping all user input
Why it's wrong here
Escaping input is error-prone and context-dependent; it fails where queries are built by string concatenation across dynamic fragments. Parameterised queries, which send SQL and data on separate protocol paths, are the correct control. Escaping is tempting because it addresses the immediate symptom in simple cases, but it cannot guarantee safety across all database dialects and encodings.
- ✗
Using stored procedures exclusively
Why it's wrong here
Stored procedures still execute dynamic SQL if they concatenate parameters, so injection remains possible. Parameterised queries, which send data separately from the SQL text, prevent it. Stored procedures would be the right choice for centralising and reusing database logic across applications.
- ✗
Input length validation
Why it's wrong here
Length validation constrains input size but does not stop crafted payloads within that length altering query structure. Parameterised queries bind user data as values, never as SQL syntax. Length validation would be the right choice for limiting buffer or field overflow risks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.