CompTIA DataSys+ (DS0-001)Data and Database SecurityHard
A multinational corporation is implementing a new customer relationship management (CRM) system that will store customer personal data across various regions. To comply with diverse data protection regulations (e.g., GDPR, CCPA), the company needs a mechanism to apply different data handling rules to data originating from different jurisdictions while keeping it within a single logical database. Which security concept BEST supports this requirement?
- AHomomorphic encryption
- BData federation
- CFine-grained access control (FGAC)
- DDatabase sharding
Show answer & explanationAnswer & explanation
Correct answer: C. Fine-grained access control (FGAC)
Fine-grained access control (FGAC), often implemented via Virtual Private Database (VPD) or row-level security, allows different data handling rules to be applied dynamically based on the user's role, location, or other attributes. This enables a single logical database to present different views or restrictions on data based on jurisdictional requirements, ensuring compliance without needing separate physical databases.
Why the other options are wrong
- A. Homomorphic encryption allows computations on encrypted data but doesn't directly address applying different access rules based on data origin or user jurisdiction.
- B. Data federation integrates data from multiple disparate sources but doesn't inherently provide a mechanism to apply dynamic, jurisdiction-specific access rules within a unified view.
- D. Database sharding distributes data across multiple physical databases, which could support data residency but doesn't apply different rules within a single logical database based on jurisdiction.
Fine-Grained Access Control (FGAC)
A security mechanism that restricts user access to specific rows, columns, or cells within a database table based on defined policies and user context.
- Also known as Row-Level Security (RLS) or Virtual Private Database (VPD).
- Enforces security policies dynamically at query execution time.
- Crucial for multi-tenant environments and diverse regulatory compliance.
Memory trick: Dynamic rules mean each user sees only what their 'passport' allows.