HomeSubjectsUniversityBlogAbout

Database Security

Topic in Databases

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Database security protects stored data from unauthorized access, change and disclosure through access control, encryption, auditing and inference control. Access control questions compare discretionary control with GRANT and REVOKE, mandatory control based on the Bell-LaPadula model, and role-based access control. SQL injection appears often, including blind and second-order variants and the defences of parameterized queries and input validation. Other items cover inference attacks on statistical databases, audit trails, transparent data encryption, static versus dynamic data masking, and privacy techniques such as k-anonymity, l-diversity and differential privacy.

Below are 30 practice questions from a pool of 210 Database Security MCQs, one of 17 topics in Databases. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Database SecurityEasy

Q1. Database security aims to protect the database from:

  1. A.Faster queries and improved execution performance
  2. B.Unauthorized access, modification, and destruction✓ Correct
  3. C.Larger storage capacity on the available disk space
  4. D.Better indexing and optimized data retrieval speed

Explanation

Database security protects data integrity, confidentiality, and availability from unauthorized activities.

Report an error in this question

Database SecurityEasy

Q2. Authentication in database security verifies:

  1. A.The identity of a user✓ Correct
  2. B.The number of indexes
  3. C.The speed of queries
  4. D.The size of tables

Explanation

Authentication verifies that a user is who they claim to be.

Report an error in this question

Database SecurityEasy

Q3. Authorization in database security determines:

  1. A.The operating system and hardware details
  2. B.What actions a user is permitted to perform✓ Correct
  3. C.The database version and release number
  4. D.The user password and login credentials

Explanation

Authorization determines the privileges and operations a user is allowed to perform.

Report an error in this question

Database SecurityEasy

Q4. The SQL GRANT statement is used to:

  1. A.Create tables in database
  2. B.Remove privileges from users
  3. C.Delete data from tables
  4. D.Give privileges to users✓ Correct

Explanation

GRANT assigns specific database privileges to users or roles.

Report an error in this question

Database SecurityEasy

Q5. The SQL REVOKE statement is used to:

  1. A.Remove previously granted privileges✓ Correct
  2. B.Insert data into existing table records
  3. C.Grant new privileges to database users
  4. D.Create views on top of the base tables

Explanation

REVOKE removes privileges that were previously granted to users or roles.

Report an error in this question

Database SecurityEasy

Q6. A database role is:

  1. A.An index structure built on columns for faster data retrieval
  2. B.A type of table used to store data records within the database
  3. C.A named collection of privileges that can be assigned to users✓ Correct
  4. D.A query optimization technique to improve execution planning

Explanation

A role groups privileges together, making it easier to manage permissions for multiple users.

Report an error in this question

Database SecurityEasy

Q7. Encryption in database security is used to:

  1. A.Compress data to reduce the amount of storage space it requires
  2. B.Create indexes on columns for faster retrieval of requested records
  3. C.Convert data into an unreadable format to prevent unauthorized access✓ Correct
  4. D.Speed up queries by creating cached copies of frequently used results

Explanation

Encryption transforms data into ciphertext, making it unreadable without the proper decryption key.

Report an error in this question

Database SecurityEasy

Q8. An audit trail in a database records:

  1. A.All operations performed on the database for security monitoring✓ Correct
  2. B.Only DDL operations like CREATE, ALTER, and DROP table commands
  3. C.Only user logins and their session authentication event details
  4. D.Only SELECT queries that have been executed against stored tables

Explanation

An audit trail logs database operations to track who did what and when.

Report an error in this question

Database SecurityEasy

Q9. SQL injection is a type of:

  1. A.Indexing strategy used for speeding up data retrieval from the tables
  2. B.Security attack that exploits vulnerabilities in SQL query construction✓ Correct
  3. C.Database optimization technique that improves overall query performance
  4. D.Backup method used for creating copies of the database for recovery

Explanation

SQL injection is an attack where malicious SQL code is inserted into queries through user input.

Report an error in this question

Database SecurityEasy

Q10. The principle of least privilege means:

  1. A.All users should have full access to every table in the database
  2. B.Users should have only the minimum privileges needed for their tasks✓ Correct
  3. C.No privileges should be granted to any user in the database
  4. D.Only administrators should be allowed to use the database system

Explanation

Least privilege grants users only the permissions necessary to perform their specific duties.

Report an error in this question

Database SecurityMedium

Q11. Mandatory Access Control (MAC) is based on:

  1. A.Security labels and clearance levels assigned to subjects and objects✓ Correct
  2. B.User discretion in deciding who can access which database objects
  3. C.No access control at all with every user having full open access
  4. D.Role assignments only without any additional security label checks

Explanation

MAC uses security labels (classifications) on data objects and clearance levels on subjects to control access.

Report an error in this question

Database SecurityMedium

Q12. Discretionary Access Control (DAC) allows:

  1. A.Data owners to grant and revoke access to other users✓ Correct
  2. B.No access control with all data open to every user
  3. C.Access based on security clearance only in the system
  4. D.Only the DBA to control access to all database objects

Explanation

DAC allows data owners to control access to their data by granting/revoking privileges at their discretion.

Report an error in this question

Database SecurityMedium

Q13. Role-Based Access Control (RBAC) assigns privileges to:

  1. A.Individual users only without grouping
  2. B.Queries only without role management
  3. C.Tables only without any user control
  4. D.Roles, which are then assigned to users✓ Correct

Explanation

RBAC assigns privileges to roles, and users are assigned to appropriate roles.

Report an error in this question

Database SecurityMedium

Q14. The Bell-LaPadula model enforces:

  1. A.Only read access controls without write restrictions
  2. B.No read-up and no write-down rules for confidentiality✓ Correct
  3. C.No rules at all for controlling information access
  4. D.Only write access controls without read restrictions

Explanation

Bell-LaPadula enforces 'no read up' (simple security) and 'no write down' (star property) for confidentiality.

Report an error in this question

Database SecurityMedium

Q15. Data masking in database security:

  1. A.Encrypts entire databases for secure data storage
  2. B.Deletes all data from the tables in the database
  3. C.Replaces sensitive data with realistic but fake data✓ Correct
  4. D.Creates copies of data for backup and recovery use

Explanation

Data masking replaces sensitive data with fictitious but realistic data for non-production environments.

Report an error in this question

Database SecurityMedium

Q16. A view can provide security by:

  1. A.Deleting sensitive records from the database tables
  2. B.Encrypting all data stored in the underlying tables
  3. C.Creating new tables with restricted column schemas
  4. D.Restricting which columns and rows a user can see✓ Correct

Explanation

Views can restrict access to specific columns and rows, providing a security layer over base tables.

Report an error in this question

Database SecurityMedium

Q17. Virtual Private Database (VPD) provides:

  1. A.Only audit logging without any enforcement of access policies
  2. B.Column-level encryption only without any row-level restrictions
  3. C.No security features of any kind for the database application
  4. D.Row-level security by automatically adding conditions to queries✓ Correct

Explanation

VPD automatically appends security predicates to queries, filtering rows based on user context.

Report an error in this question

Database SecurityMedium

Q18. Transparent Data Encryption (TDE) encrypts:

  1. A.Query results only sent to clients
  2. B.Log files only on the disk storage
  3. C.Data in transit only on the network
  4. D.Data at rest on the storage media✓ Correct

Explanation

TDE encrypts database files on disk (at rest) transparently, without requiring application changes.

Report an error in this question

Database SecurityMedium

Q19. Database activity monitoring (DAM) is used to:

  1. A.Optimize storage allocation across available disk partitions
  2. B.Speed up queries by caching frequently accessed data in memory
  3. C.Create backups of the database on a scheduled periodic basis
  4. D.Monitor and record database activity in real-time for security✓ Correct

Explanation

DAM solutions monitor database traffic in real-time to detect unauthorized activities and policy violations.

Report an error in this question

Database SecurityMedium

Q20. The GRANT OPTION in SQL allows:

  1. A.Creating tables and views in the database schema at will
  2. B.Revoking all privileges from every user in the database
  3. C.Deleting databases and all their data from the server
  4. D.A grantee to further grant the same privilege to other users✓ Correct

Explanation

GRANT OPTION allows the recipient of a privilege to pass that privilege on to other users.

Report an error in this question

Database SecurityHard

Q21. Statistical database security addresses the problem of:

  1. A.Managing user roles and their assigned privileges set
  2. B.Creating backup copies of the database for recovery
  3. C.Inferring individual data from aggregate query results✓ Correct
  4. D.Encrypting data at rest on the physical storage media

Explanation

Statistical database security prevents users from deducing individual values through carefully crafted aggregate queries.

Report an error in this question

Database SecurityHard

Q22. The inference problem in database security occurs when:

  1. A.No queries are allowed to be executed against the tables
  2. B.Users deduce restricted information from permitted queries✓ Correct
  3. C.Users have direct database access without any restrictions
  4. D.All data is encrypted and cannot be read without the key

Explanation

The inference problem occurs when users can deduce confidential information by combining permitted query results.

Report an error in this question

Database SecurityHard

Q23. Label-based security in databases assigns:

  1. A.Sensitivity labels to data rows and clearance levels to users✓ Correct
  2. B.Labels only to tables without any row-level classification
  3. C.No labels to any data regardless of its sensitivity or nature
  4. D.Random access permissions to all users without any restrictions

Explanation

Label-based security assigns sensitivity labels to individual rows and clearance levels to users for fine-grained access control.

Report an error in this question

Database SecurityHard

Q24. Homomorphic encryption allows:

  1. A.Faster decryption of data using optimized algorithms
  2. B.Only reading encrypted data without any modifications
  3. C.Computations on encrypted data without decrypting it✓ Correct
  4. D.Only writing encrypted data without reading it first

Explanation

Homomorphic encryption enables performing computations on ciphertext, producing encrypted results that match the plaintext computation.

Report an error in this question

Database SecurityHard

Q25. Database firewall works by:

  1. A.Encrypting all data stored in the database tables and log files
  2. B.Only blocking network traffic without inspecting SQL statements
  3. C.Creating physical firewalls around the database server hardware
  4. D.Monitoring SQL traffic and blocking unauthorized or suspicious queries✓ Correct

Explanation

A database firewall monitors SQL queries in real-time and blocks those that violate security policies.

Report an error in this question

Database SecurityHard

Q26. The k-anonymity privacy model ensures:

  1. A.Only k users can access the database at any given time during concurrent operations
  2. B.Data is stored in k copies across different sites for redundancy and availability
  3. C.All data is encrypted using a key of length k bits for secure storage and retrieval
  4. D.Each record is indistinguishable from at least k-1 other records on quasi-identifiers✓ Correct

Explanation

K-anonymity ensures that each record shares quasi-identifier values with at least k-1 other records to prevent re-identification.

Report an error in this question

Database SecurityHard

Q27. Differential privacy provides:

  1. A.Full access to all data without any restrictions or privacy controls
  2. B.Only physical security measures without any mathematical foundations
  3. C.No privacy guarantees of any kind for the data stored in the database
  4. D.Mathematical guarantees that query results do not reveal individual data✓ Correct

Explanation

Differential privacy adds controlled noise to query results to provide mathematical privacy guarantees for individuals.

Report an error in this question

Database SecurityHard

Q28. A privilege graph is used to:

  1. A.Track the flow of granted privileges among users✓ Correct
  2. B.Design ER diagrams for conceptual data modeling
  3. C.Optimize query execution plans for better speed
  4. D.Create indexes on columns for fast data retrieval

Explanation

A privilege graph shows how privileges flow from grantor to grantee, useful for cascade revocation analysis.

Report an error in this question

Database SecurityHard

Q29. Cascading revocation in SQL means:

  1. A.Revoking a privilege also revokes it from all users who received it through the original grant✓ Correct
  2. B.No revocation occurs and the privilege remains active for all users who currently have it
  3. C.Only the specified user loses the privilege and no other users are affected by the revocation
  4. D.All database privileges for every user are revoked regardless of the specific grant involved

Explanation

With CASCADE, revoking a privilege also revokes it from all users who received it transitively through that grant.

Report an error in this question

Database SecurityHard

Q30. Column-level encryption differs from TDE in that:

  1. A.It encrypts specific columns rather than entire database files✓ Correct
  2. B.It encrypts only at the network level rather than at storage level
  3. C.It encrypts only table names rather than the actual column data
  4. D.It is less secure than TDE because it covers fewer data elements

Explanation

Column-level encryption selectively encrypts individual columns containing sensitive data, while TDE encrypts entire database files.

Report an error in this question

Ready to test yourself on Database Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Database Security Quiz