CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A database administrator is configuring a new production database that stores sensitive financial transactions. Due to regulatory requirements, all access to this database must be recorded, including successful and failed login attempts, as well as modifications to critical tables. Which of the following database features should be primarily configured to meet these requirements?
- AColumn-level encryption
- BData masking
- CAuditing policies
- DVirtual Private Database (VPD)
Show answer & explanationAnswer & explanation
Correct answer: C. Auditing policies
Auditing policies are designed to record specific database activities, such as login attempts (both successful and failed) and data manipulation language (DML) operations on critical tables. This directly addresses the need for comprehensive logging of access and modifications for regulatory compliance.
Why the other options are wrong
- A. Column-level encryption protects specific data elements but doesn't log access or modifications.
- B. Data masking obscures sensitive data for non-production environments but doesn't record access.
- D. VPD applies fine-grained access control based on context but doesn't inherently record all access attempts or modifications.
Database Auditing
The process of recording specific database events and actions to provide an accountability trail for security, compliance, and troubleshooting.
- Records login attempts (success/failure).
- Tracks DML (Data Manipulation Language) and DDL (Data Definition Language) operations.
- Essential for regulatory compliance and security monitoring.
Memory trick: Accountability means keeping a detailed log of every action.