Secure Coding Practices · question
Q.03 of 28
What is SQL injection and how can it be prevented?
← All Secure Coding Practices questions
Re-explain
SQL injection occurs when user input is directly concatenated into SQL queries, allowing attackers to manipulate the database.
Example of vulnerable code:
# VULNERABLE
query = f"SELECT * FROM users WHERE username = '{username}'"
Attack example: username = "admin'; DROP TABLE users; --"
Prevention methods:
- Parameterized queries/Prepared statements (most effective)
- Stored procedures (when properly implemented)
- Input validation (whitelist approach)
- Least privilege principle for database accounts
- Web Application Firewalls (additional layer)
Secure example:
# SECURE - Using parameterized query
cursor.execute("SELECT * FROM users WHERE username = %s", (username,))
Rewriting in plainer words…
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
The model's verdict: “”
This answer is explained by a shared concept diagram -
open →
Point the redraw:
How well did you know this?
AI:
Saved in this browser - sign in to keep your review list.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Keep going - a few more words and AI can grade it.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.
Pro · $10/mo
24 of 28 Secure Coding Practices answers are gated.
Full answers, code samples, AI explanations - simpler, deeper, or as an interactive diagram. Cancel anytime.
-
Full answers + code
-
AI explain - simpler, deeper, or visualized
-
1,000 AI credits / month
-
Cancel anytime