nerdexam
Microsoft

70-516 · Question #50

You use Microsoft Visual Studio 2010 and .NET Framework 4.0 to create an application. The application connects to a Microsoft SQL Server 2008 database. The application contains the following code…

The correct answer is A. string SQL = "SELECT * FROM Customer Where " +. SqlParameterCollection.AddWithValue Method us/library/system.data.sqlclient.sqlparametercollection.addwithvalue.aspx)

Manipulating and Validating Data

Question

You use Microsoft Visual Studio 2010 and .NET Framework 4.0 to create an application. The application connects to a Microsoft SQL Server 2008 database. The application contains the following code segment. string SQL = string.Format( “SELECT * FROM Customer WHERE CompanyName LIKE ‘%{0}%’, companyName); var cmd = new SqlCommand(SQL, con); You need to reduce the vulnerability to SQL injection attacks. Which code segment should you use?

Options

  • Astring SQL = "SELECT * FROM Customer Where " +
  • Bstring SQL = "SELECT * FROM Customer Where " +
  • Cstring SQL = string.Format("SELECT * FROM " +
  • Dstring SQL = "SELECT" * FROM Customer @companyName;

How the community answered

(35 responses)
  • A
    80% (28)
  • B
    3% (1)
  • C
    11% (4)
  • D
    6% (2)

Explanation

SqlParameterCollection.AddWithValue Method us/library/system.data.sqlclient.sqlparametercollection.addwithvalue.aspx)

Topics

#SQL injection#parameterized queries#SqlCommand#input validation

Community Discussion

No community discussion yet for this question.

Full 70-516 Practice