CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A large enterprise database contains millions of records, including sensitive customer data and intellectual property. The security team wants to implement a solution that provides real-time, continuous monitoring of all SQL statements executed against the database, including stored procedures, and the ability to detect anomalous behavior without significantly impacting database performance. Which advanced security solution is BEST suited for this requirement?

  1. AOperating system-level auditing
  2. BDatabase activity monitoring (DAM) system
  3. CStandard database logging (e.g., SQL Server Audit)
  4. DNetwork Intrusion Detection System (NIDS)
Show answer & explanation

Correct answer: B. Database activity monitoring (DAM) system

A Database Activity Monitoring (DAM) system is specifically designed for real-time, continuous monitoring of all database activity, including SQL statements, stored procedures, and administrative commands, directly from the database or network traffic. It can detect anomalous behavior without relying on native database logging, which often has performance overhead or lacks the granularity needed for security analysis.

Why the other options are wrong

  • A. OS-level auditing monitors file access or process execution but does not provide granular visibility into SQL statements executed within the database engine itself.
  • C. Standard database logging can be configured for auditing but often has performance overhead when logging all statements and may lack advanced anomaly detection capabilities.
  • D. NIDS monitors network traffic generally but lacks the deep understanding of SQL syntax and database context to effectively analyze all SQL statements and stored procedures.

Database Activity Monitoring (DAM)

A security technology that monitors and analyzes database activity in real-time, providing visibility into SQL statements, user access, and potential threats.

  • Monitors all SQL traffic, stored procedures, and administrative commands.
  • Detects anomalous behavior and potential insider threats.
  • Provides a continuous audit trail for compliance and forensics.

Memory trick: Surveillance needs a watchful eye that understands database language.

More Data and Database Security questions