CompTIA DataSys+ (DS0-001)Data and Database SecurityHard
A database administrator is tasked with implementing a security measure that ensures users can only access the specific rows and columns of data relevant to their job function, even within a table they are authorized to view. For example, a regional sales manager should only see sales data for their region, and not for other regions. What advanced access control mechanism would best achieve this granular level of data restriction?
- ADiscretionary Access Control (DAC)
- BRole-Based Access Control (RBAC)
- CFine-Grained Access Control (FGAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Fine-Grained Access Control (FGAC)
Fine-Grained Access Control (FGAC), often implemented through row-level security (RLS) and column-level security (CLS), allows administrators to define policies that restrict access to specific rows and columns within a table based on user attributes, roles, or context. This directly addresses the requirement for highly granular data restriction.
Why the other options are wrong
- A. DAC allows object owners to grant/revoke access, which is too broad and not granular enough for this scenario.
- B. RBAC assigns permissions based on roles, but typically at the object (table, view) level, not individual rows/columns.
- D. MAC is a highly restrictive model based on security labels, typically used in high-security environments, not for job-function-based row/column access.
Fine-Grained Access Control (FGAC)
Fine-Grained Access Control (FGAC) is an advanced access control mechanism that allows database administrators to define highly specific authorization policies, often down to the individual row and column level within a table, based on user context or attributes.
- Provides row-level security (RLS) and column-level security (CLS).
- Restricts data visibility based on user attributes or policies.
- More granular than traditional RBAC.
Memory trick: FGAC: Every cell has its own key.