CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A database administrator is tasked with implementing a security measure that ensures users can only access the specific rows and columns of data relevant to their job function, even within a table they are authorized to view. For example, a regional sales manager should only see sales data for their region, and not for other regions. What advanced access control mechanism would best achieve this granular level of data restriction?

  1. ADiscretionary Access Control (DAC)
  2. BRole-Based Access Control (RBAC)
  3. CFine-Grained Access Control (FGAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: C. Fine-Grained Access Control (FGAC)

Fine-Grained Access Control (FGAC), often implemented through row-level security (RLS) and column-level security (CLS), allows administrators to define policies that restrict access to specific rows and columns within a table based on user attributes, roles, or context. This directly addresses the requirement for highly granular data restriction.

Why the other options are wrong

  • A. DAC allows object owners to grant/revoke access, which is too broad and not granular enough for this scenario.
  • B. RBAC assigns permissions based on roles, but typically at the object (table, view) level, not individual rows/columns.
  • D. MAC is a highly restrictive model based on security labels, typically used in high-security environments, not for job-function-based row/column access.

Fine-Grained Access Control (FGAC)

Fine-Grained Access Control (FGAC) is an advanced access control mechanism that allows database administrators to define highly specific authorization policies, often down to the individual row and column level within a table, based on user context or attributes.

  • Provides row-level security (RLS) and column-level security (CLS).
  • Restricts data visibility based on user attributes or policies.
  • More granular than traditional RBAC.

Memory trick: FGAC: Every cell has its own key.

More Data and Database Security questions