CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A multinational corporation is implementing a new customer relationship management (CRM) system that will store customer personal data across various regions. To comply with diverse data protection regulations (e.g., GDPR, CCPA), the company needs a mechanism to apply different data handling rules to data originating from different jurisdictions while keeping it within a single logical database. Which security concept BEST supports this requirement?

  1. AHomomorphic encryption
  2. BData federation
  3. CFine-grained access control (FGAC)
  4. DDatabase sharding
Show answer & explanation

Correct answer: C. Fine-grained access control (FGAC)

Fine-grained access control (FGAC), often implemented via Virtual Private Database (VPD) or row-level security, allows different data handling rules to be applied dynamically based on the user's role, location, or other attributes. This enables a single logical database to present different views or restrictions on data based on jurisdictional requirements, ensuring compliance without needing separate physical databases.

Why the other options are wrong

  • A. Homomorphic encryption allows computations on encrypted data but doesn't directly address applying different access rules based on data origin or user jurisdiction.
  • B. Data federation integrates data from multiple disparate sources but doesn't inherently provide a mechanism to apply dynamic, jurisdiction-specific access rules within a unified view.
  • D. Database sharding distributes data across multiple physical databases, which could support data residency but doesn't apply different rules within a single logical database based on jurisdiction.

Fine-Grained Access Control (FGAC)

A security mechanism that restricts user access to specific rows, columns, or cells within a database table based on defined policies and user context.

  • Also known as Row-Level Security (RLS) or Virtual Private Database (VPD).
  • Enforces security policies dynamically at query execution time.
  • Crucial for multi-tenant environments and diverse regulatory compliance.

Memory trick: Dynamic rules mean each user sees only what their 'passport' allows.

More Data and Database Security questions