adplus-dvertising
frame-decoration

Question

What are the two best ways to protect against SQL injection attacks?

a.

Encryption and secure sockets layer (SSL)

b.

Input validation and least privilege restrictions on database access

c.

Firewalls and intrusion detection systems (IDS)

d.

Multi-factor authentication and access control lists (ACLs)

Answer: (b).Input validation and least privilege restrictions on database access Explanation:The two best ways to protect against SQL injection attacks are input validation and the enforcement of least privilege restrictions on database access.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What are the two best ways to protect against SQL injection attacks?

Similar Questions

Discover Related MCQs

Q. Cross-Site Scripting (XSS) vulnerabilities can trick users into executing malicious code on a trusted website.

Q. What should cybersecurity analysts do when discovering potential XSS vulnerabilities?

Q. How do vulnerability scanners usually rank detected issues?

Q. What can false positive reports in vulnerability scans lead to?

Q. What is a measure used in the Common Vulnerability Scoring System (CVSS) to assess vulnerabilities?

Q. What should penetration testers be careful to watch for when interpreting vulnerability reports?

Q. What does Cross-Site Scripting (XSS) aim to achieve?

Q. What crucial information is typically included in vulnerability scan reports, in addition to details about vulnerabilities?

Q. What does the CVSS base score measure on a 10-point scale?

Q. Name two common sources of vulnerabilities.

Q. What type of attacks typically exploit application flaws?

Q. What is a common source of vulnerabilities in network devices?

Q. What should network administrators ensure to patch security issues in network devices?

Q. What causes vulnerabilities in SSL and TLS encryption?

Q. What should administrators do to protect against virtual machine escape attacks in virtualized infrastructure?

Q. What does the CVSS base score consider regarding the impact of a vulnerability?

Q. What is a suggested solution often provided in vulnerability scan reports?

Q. Tom is reviewing a vulnerability scan report and finds that one of the servers on his network suffers from an internal IP address disclosure vulnerability. What protocol is likely in use on this network that resulted in this vulnerability?

Q. Which one of the CVSS metrics would contain information about the type of user account an attacker must use to execute an attack?

Q. Which one of the following values for the CVSS attack complexity metric would indicate that the specified attack is simplest to exploit?