Q17Application Deployment and SecurityMultiple answers
Which two methods defend against injection attacks? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 7
23
I think A D
E - using dropdown only for a fixed set of values
10
A and D
Elimination:
B. Trim whitespace
> whitespace isn't the issue with injection attacks
C. limit text areas to 255 characters
> You could still perform an injection with fewer than 255 characters.
E. only use dropdown, checkbox, and radio button fields
> This is client-side code that stops users from injecting through a browser, but it does not stop a scripted attack.
5
It is A and D.
Reference: https://www.hacksplaining.com/prevention/sql-injection
A, D 3
Selected Answer: AD
Correct answers: A & D
Against injection attacks, these help:
- Escaping Inputs/Sanitizing Inputs
- Principle of Least Privilege
- Parameterized queries and prepared statements
- Prevent all SQL-generated error messages from being displayed to the end user
- Password Hashing
- Third Party Authentication
- Data validation process to assess data against a set of rules
- Intrusion prevention system (IPS) or a next-generation firewall (NGFW)
A, D 2
Selected Answer: AD
a, d ...
A, D 2
Selected Answer: AD
A and D, dropdowns don't protect, they only limit input, but can be ignored if you know what you are doing (like pressing F12)
A, D 2
Selected Answer: AD
A and D are right
The following defense methods are available:
- Escaping Inputs/Sanitizing Inputs
- Principle of Least Privilege
- Parameterized queries and prepared statements
- Prevent all SQL-generated error messages from being displayed to the end user
- Password Hashing
- Third Party Authentication
- Data validation process to assess data against a set of rules
- Intrusion prevention system (IPS) or a next-generation firewall (NGFW)