ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During a peer review of a new cloud-native microservice, you notice a function that builds a SQL statement by concatenating user-supplied JSON field values before passing it to a managed database service. The microservice is intended for a multi-tenant SaaS platform, and no additional database controls are in place. To avoid introducing a common cloud application vulnerability, which change to the code base provides the MOST effective remediation?

  • Escape all single quotes in the user-supplied fields before concatenating them into the SQL string.

  • Apply JSON output encoding to the query results returned to the client.

  • Replace the concatenated query with parameterized (prepared) SQL statements that bind user input as parameters.

  • Enable transparent data encryption (TDE) on the managed database to protect the records at rest.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot