1.:format (that period is a concatenation period)
2.h is a helper method that escapes special characters to sanitize malicious input
3.a script that alters the structure of the underlying database
4.the method within the controller to call
Answer:2