Absolutely use the runPrepUpdate.
runPrepUpdate
If you have a competent DB brand and JDBC driver, you have another, more efficient option: