What is SQL injection and why is it relevant to PCI DSS?
- A.An attack where malicious SQL code is inserted into application queries, potentially allowing unauthorized access to cardholder data in databases
- B.A data backup method, because scan frequency may be reduced to annual where no vulnerabilities were found previously for outsourced payment pages
- C.A database optimization technique, which Requirement 3.2.1 subjects to documented retention limits and a process at least every three months to find and securely delete anything exceeding them
- D.A network scanning technique, on the basis that secure coding training for developers is required once at induction only for e-commerce merchants
Why A is correct
SQL injection allows attackers to manipulate database queries through malicious input, potentially exposing stored cardholder data.
Know someone studying for PCI DSS? Send them this one.