Neither are particularly good behaviors, but as a "computer guy" I think your public-facing API (science fair admissions) should validate its inputs. There are people out there who send know malicious requests to endpoints, you know.
Instead of blaming an underage student I'd reevaluate all of their prior nominations. Chances of dragons being there.