- Home
- All questions
- Question 469
CISSP study material · question 469 of 500
A team relies solely on positive server-side input validation to stop injection. Why does OWASP describe this as incomplete?
Show the answer
Answer: A. Many applications legitimately require special characters, for example in free text areas and mobile interfaces.
OWASP calls positive server-side input validation not a complete defence, because many applications require special characters, such as text areas or interfaces for mobile applications.
Source: OWASP Top 10 A05:2025 (OWASP) — OWASP Top 10:2025 A05 Injection > How to prevent