Suggested answer

Dynamic SOQL using Database.query(queryString) allows runtime-built queries but introduces SOQL injection risk. Safe practices:

1. Bind variables: Use ':variableName' in the string — variable values are not interpreted as SOQL. However, bind variables in dynamic SOQL reference the variable by name in scope at the query call — be careful.
2. String.escapeSingleQuotes(): Escapes user-supplied strings before inserting into the query.
3. Whitelisting: Only allow known field/object names from a validated list — never allow raw user input to define field names or object names.
4. Schema methods: Validate object/field existence using Schema.getGlobalDescribe() before including them in queries.
5. Type-safe patterns: Use strongly-typed selector classes rather than building raw dynamic queries throughout the codebase.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.