CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A company is preparing for a GDPR compliance audit. The auditor requires proof that all access to sensitive customer data is recorded, including who accessed it, when, and what actions were performed. The company needs a mechanism to maintain an immutable log of these activities. Which database security feature should the company ensure is fully enabled and configured?
- ARole-Based Access Control (RBAC)
- BData Encryption at Rest
- CData Loss Prevention (DLP)
- DDatabase Auditing
Show answer & explanationAnswer & explanation
Correct answer: D. Database Auditing
Database auditing involves recording and reviewing database activities, providing an immutable log of who accessed what data, when, and what operations were performed. This directly addresses the GDPR requirement for accountability and proof of access.
Why the other options are wrong
- A. RBAC controls who can access data but does not inherently log access attempts or actions.
- B. Data encryption protects data confidentiality but does not record access events.
- C. DLP prevents unauthorized data egress but doesn't primarily focus on logging internal database access actions.
Database Auditing
The process of monitoring and recording database activities, including user actions, data changes, and system events.
- Provides an immutable log for security, compliance, and forensic analysis.
- Helps detect unauthorized access attempts or suspicious activities.
- Can generate significant data volume, requiring careful configuration and storage.
Memory trick: Audits record every step for the judge.