- Home
- All questions
- Question 581
CompTIA Security+ study material · question 581 of 611
Where does escaping input sit among OWASP's SQL injection defences?
Show the answer
Answer: C. It is a last resort, being database-specific and easy to get wrong
Parameterised queries come first; escaping is reserved for cases where nothing else is possible.
Source: OWASP SQL Injection Prevention Cheat Sheet (OWASP) — OWASP SQL Injection Prevention Cheat Sheet › Defense Options