Security Protocols & Access Control Flashcards
9 cards from real ADC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Security Protocols & Access Control flashcards as text
What is the main purpose of access control in a database?
Answer: To restrict unauthorized data access.
The main purpose of access control in a database is to manage and restrict who can view, modify, or delete data. It ensures that only authorized users or applications can perform specific operations, thereby protecting sensitive information and maintaining data security and integrity. This is a critical component of any robust database security strategy.
What does authentication verify?
Answer: User identity.
Authentication is the process of verifying the identity of a user, system, or application attempting to access a database. It typically involves checking credentials like usernames and passwords against stored information. Successful authentication confirms that the entity is who they claim to be, granting them access based on their authorized permissions and ensuring system security.
Which of the following is an example of multi-factor authentication?
Answer: Password and fingerprint.
Multi-factor authentication (MFA) requires users to provide two or more distinct verification factors from different categories to gain access. A password represents 'something you know,' while a fingerprint represents 'something you are.' Combining these significantly enhances security by requiring multiple proofs of identity.
What is the principle of least privilege?
Answer: Users get minimum access rights.
The Principle of Least Privilege dictates that users, programs, or processes should be granted only the minimum necessary permissions to perform their specific tasks. This security best practice limits the potential damage from compromised accounts or systems, reducing the attack surface and preventing unauthorized actions.
Which SQL command controls user access to database objects?
Answer: GRANT
The `GRANT` SQL command is part of Data Control Language (DCL) and is specifically used to give users or roles permissions to perform certain operations on database objects, such as tables, views, or stored procedures. It allows database administrators to manage who can access and manipulate data within the database.
What does role-based access control (RBAC) rely on?
Answer: User roles.
Role-Based Access Control (RBAC) is an access control model that regulates access to resources based on the individual's role within an organization. Instead of assigning permissions directly to users, permissions are assigned to specific roles, and users are then assigned to one or more roles, simplifying access management and ensuring consistent security policies.
What is the function of database auditing?
Answer: Monitors and logs database activity.
Database auditing involves monitoring and recording specific actions performed within a database, such as data access, modifications, or administrative operations. This function is crucial for security, compliance, and accountability, as it provides a historical record of who did what, when, and where, helping to detect and investigate suspicious activities.
What risk does SQL injection pose?
Answer: Allows unauthorized access or manipulation of data.
SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution. This vulnerability allows attackers to bypass authentication, retrieve sensitive data, modify database content, or even gain full control over the database server, posing a severe security risk.
How can you prevent SQL injection attacks?
Answer: Use parameterized queries.
Parameterized queries, also known as prepared statements, are the most effective way to prevent SQL injection attacks. They separate the SQL code from the user-supplied data, ensuring that user input is treated as literal values rather than executable commands. This prevents malicious input from altering the intended query structure.