Courseiva
Strings →hardMultiple Choice

PCAP Strings Practice Question

A programmer is writing a script to generate SQL queries safely. They need to escape single quotes in user-provided strings to prevent injection. Which approach is most robust?

⚠ Common exam trap

Python Institute often tests the misconception that backslash escaping is universal in SQL, leading candidates to choose Option B, but the PCAP exam expects knowledge of the standard SQL escape mechanism (doubling quotes) as the most robust method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s.replace("'", "''")

In SQL, single quotes are escaped by doubling them (''), not by using backslashes. This is the standard escape mechanism defined by the SQL standard (ISO/IEC 9075) and is supported by databases like PostgreSQL, SQLite, and Oracle. Using `s.replace("'", "''")` ensures that a single quote in user input becomes two single quotes in the SQL string, preventing injection while preserving the literal quote.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    s.replace("\\'", "'")

    Why it's wrong here

    This replaces any occurrence of backslash followed by a single quote with a bare single quote, so it does not protect a quote that would close the SQL literal. Since user input containing ' remains unchanged, the quote is still able to terminate the string and allow injected SQL. Worse, if the database expects backslash escapes, this call strips the escape character and leaves the dangerous quote active.

  • ✗

    s.replace("'", "\\'")

    Why it's wrong here

    This prepends a backslash before every single quote using the Python string literal "\\'", which is a common C-style escape. However, the SQL standard does not recognize a backslash as an escape character for string literals; only a doubled quote is guaranteed to work across database systems. In a standard-conforming DBMS, the backslash is stored as a literal character and the quote still ends the string, so injection remains possible.

  • ✗

    s.strip("'")

    Why it's wrong here

    This removes all leading and trailing occurrences of the quote character from the value instead of escaping embedded quotes. Any quote in the middle of the string remains untouched, allowing it to prematurely close the SQL string literal. It also silently corrupts data by deleting legitimate quote characters from the edges of the value, so it is both unsafe and lossy.

  • ✓

    s.replace("'", "''")

    Why this is correct

    This doubles every single quote, which is the standard SQL way to include a literal quote inside a string: the DBMS sees '' as an escaped quote and does not treat the second quote as the end of the literal. By replacing all occurrences of ' with '', every potentially dangerous quote is neutralized, preventing break-out SQL injection when building queries from unsanitized input.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCAP question from scratch — 421 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCAP practice question is part of Courseiva's free Python Institute certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCAP exam.