For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA ISC Practice Exam 3Question 72
    Medium1 markMultiple Choice
    Area II: SecurityApplication SecurityThreats

    CPA · Question 72 · Area II: Security

    A company uses 'Input Validation' on its web forms. Which attack does this primarily prevent?

    Answer options:

    A.

    Phishing

    B.

    SQL Injection (SQLi) and Cross-Site Scripting (XSS)

    C.

    DDoS

    D.

    Man-in-the-Middle

    How to approach this question

    Input Validation = Checking what the user types. Injection = Typing bad code.

    Full Answer

    B.SQL Injection (SQLi) and Cross-Site Scripting (XSS)✓ Correct
    Input validation ensures that data entered by users meets expected formats. This prevents attackers from injecting malicious code (like SQL commands or JavaScript) into the application.

    Common mistakes

    Thinking validation stops network attacks like DDoS.
    Question 71All questionsQuestion 73

    Practice the full CPA ISC Practice Exam 3

    82 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ05During a walkthrough of the change management process, an auditor observes that the 'Developer' r...Medium
    View all 82 questions →