Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Database SecurityEasy
Q1. Database security aims to protect the database from:
- A.Faster queries and improved execution performance
- B.Unauthorized access, modification, and destruction✓ Correct
- C.Larger storage capacity on the available disk space
- D.Better indexing and optimized data retrieval speed
Explanation
Database security protects data integrity, confidentiality, and availability from unauthorized activities.
Report an error in this question
Database SecurityEasy
Q2. Authentication in database security verifies:
- A.The identity of a user✓ Correct
- B.The number of indexes
- C.The speed of queries
- D.The size of tables
Explanation
Authentication verifies that a user is who they claim to be.
Report an error in this question
Database SecurityEasy
Q3. Authorization in database security determines:
- A.The operating system and hardware details
- B.What actions a user is permitted to perform✓ Correct
- C.The database version and release number
- D.The user password and login credentials
Explanation
Authorization determines the privileges and operations a user is allowed to perform.
Report an error in this question
Database SecurityEasy
Q4. The SQL GRANT statement is used to:
- A.Create tables in database
- B.Remove privileges from users
- C.Delete data from tables
- D.Give privileges to users✓ Correct
Explanation
GRANT assigns specific database privileges to users or roles.
Report an error in this question
Database SecurityEasy
Q5. The SQL REVOKE statement is used to:
- A.Remove previously granted privileges✓ Correct
- B.Insert data into existing table records
- C.Grant new privileges to database users
- D.Create views on top of the base tables
Explanation
REVOKE removes privileges that were previously granted to users or roles.
Report an error in this question
Database SecurityEasy
Q6. A database role is:
- A.An index structure built on columns for faster data retrieval
- B.A type of table used to store data records within the database
- C.A named collection of privileges that can be assigned to users✓ Correct
- D.A query optimization technique to improve execution planning
Explanation
A role groups privileges together, making it easier to manage permissions for multiple users.
Report an error in this question
Database SecurityEasy
Q7. Encryption in database security is used to:
- A.Compress data to reduce the amount of storage space it requires
- B.Create indexes on columns for faster retrieval of requested records
- C.Convert data into an unreadable format to prevent unauthorized access✓ Correct
- D.Speed up queries by creating cached copies of frequently used results
Explanation
Encryption transforms data into ciphertext, making it unreadable without the proper decryption key.
Report an error in this question
Database SecurityEasy
Q8. An audit trail in a database records:
- A.All operations performed on the database for security monitoring✓ Correct
- B.Only DDL operations like CREATE, ALTER, and DROP table commands
- C.Only user logins and their session authentication event details
- D.Only SELECT queries that have been executed against stored tables
Explanation
An audit trail logs database operations to track who did what and when.
Report an error in this question
Database SecurityEasy
Q9. SQL injection is a type of:
- A.Indexing strategy used for speeding up data retrieval from the tables
- B.Security attack that exploits vulnerabilities in SQL query construction✓ Correct
- C.Database optimization technique that improves overall query performance
- D.Backup method used for creating copies of the database for recovery
Explanation
SQL injection is an attack where malicious SQL code is inserted into queries through user input.
Report an error in this question
Database SecurityEasy
Q10. The principle of least privilege means:
- A.All users should have full access to every table in the database
- B.Users should have only the minimum privileges needed for their tasks✓ Correct
- C.No privileges should be granted to any user in the database
- D.Only administrators should be allowed to use the database system
Explanation
Least privilege grants users only the permissions necessary to perform their specific duties.
Report an error in this question
Database SecurityMedium
Q11. Mandatory Access Control (MAC) is based on:
- A.Security labels and clearance levels assigned to subjects and objects✓ Correct
- B.User discretion in deciding who can access which database objects
- C.No access control at all with every user having full open access
- D.Role assignments only without any additional security label checks
Explanation
MAC uses security labels (classifications) on data objects and clearance levels on subjects to control access.
Report an error in this question
Database SecurityMedium
Q12. Discretionary Access Control (DAC) allows:
- A.Data owners to grant and revoke access to other users✓ Correct
- B.No access control with all data open to every user
- C.Access based on security clearance only in the system
- D.Only the DBA to control access to all database objects
Explanation
DAC allows data owners to control access to their data by granting/revoking privileges at their discretion.
Report an error in this question
Database SecurityMedium
Q13. Role-Based Access Control (RBAC) assigns privileges to:
- A.Individual users only without grouping
- B.Queries only without role management
- C.Tables only without any user control
- D.Roles, which are then assigned to users✓ Correct
Explanation
RBAC assigns privileges to roles, and users are assigned to appropriate roles.
Report an error in this question
Database SecurityMedium
Q14. The Bell-LaPadula model enforces:
- A.Only read access controls without write restrictions
- B.No read-up and no write-down rules for confidentiality✓ Correct
- C.No rules at all for controlling information access
- D.Only write access controls without read restrictions
Explanation
Bell-LaPadula enforces 'no read up' (simple security) and 'no write down' (star property) for confidentiality.
Report an error in this question
Database SecurityMedium
Q15. Data masking in database security:
- A.Encrypts entire databases for secure data storage
- B.Deletes all data from the tables in the database
- C.Replaces sensitive data with realistic but fake data✓ Correct
- D.Creates copies of data for backup and recovery use
Explanation
Data masking replaces sensitive data with fictitious but realistic data for non-production environments.
Report an error in this question
Database SecurityMedium
Q16. A view can provide security by:
- A.Deleting sensitive records from the database tables
- B.Encrypting all data stored in the underlying tables
- C.Creating new tables with restricted column schemas
- D.Restricting which columns and rows a user can see✓ Correct
Explanation
Views can restrict access to specific columns and rows, providing a security layer over base tables.
Report an error in this question
Database SecurityMedium
Q17. Virtual Private Database (VPD) provides:
- A.Only audit logging without any enforcement of access policies
- B.Column-level encryption only without any row-level restrictions
- C.No security features of any kind for the database application
- D.Row-level security by automatically adding conditions to queries✓ Correct
Explanation
VPD automatically appends security predicates to queries, filtering rows based on user context.
Report an error in this question
Database SecurityMedium
Q18. Transparent Data Encryption (TDE) encrypts:
- A.Query results only sent to clients
- B.Log files only on the disk storage
- C.Data in transit only on the network
- D.Data at rest on the storage media✓ Correct
Explanation
TDE encrypts database files on disk (at rest) transparently, without requiring application changes.
Report an error in this question
Database SecurityMedium
Q19. Database activity monitoring (DAM) is used to:
- A.Optimize storage allocation across available disk partitions
- B.Speed up queries by caching frequently accessed data in memory
- C.Create backups of the database on a scheduled periodic basis
- D.Monitor and record database activity in real-time for security✓ Correct
Explanation
DAM solutions monitor database traffic in real-time to detect unauthorized activities and policy violations.
Report an error in this question
Database SecurityMedium
Q20. The GRANT OPTION in SQL allows:
- A.Creating tables and views in the database schema at will
- B.Revoking all privileges from every user in the database
- C.Deleting databases and all their data from the server
- D.A grantee to further grant the same privilege to other users✓ Correct
Explanation
GRANT OPTION allows the recipient of a privilege to pass that privilege on to other users.
Report an error in this question
Database SecurityHard
Q21. Statistical database security addresses the problem of:
- A.Managing user roles and their assigned privileges set
- B.Creating backup copies of the database for recovery
- C.Inferring individual data from aggregate query results✓ Correct
- D.Encrypting data at rest on the physical storage media
Explanation
Statistical database security prevents users from deducing individual values through carefully crafted aggregate queries.
Report an error in this question
Database SecurityHard
Q22. The inference problem in database security occurs when:
- A.No queries are allowed to be executed against the tables
- B.Users deduce restricted information from permitted queries✓ Correct
- C.Users have direct database access without any restrictions
- D.All data is encrypted and cannot be read without the key
Explanation
The inference problem occurs when users can deduce confidential information by combining permitted query results.
Report an error in this question
Database SecurityHard
Q23. Label-based security in databases assigns:
- A.Sensitivity labels to data rows and clearance levels to users✓ Correct
- B.Labels only to tables without any row-level classification
- C.No labels to any data regardless of its sensitivity or nature
- D.Random access permissions to all users without any restrictions
Explanation
Label-based security assigns sensitivity labels to individual rows and clearance levels to users for fine-grained access control.
Report an error in this question
Database SecurityHard
Q24. Homomorphic encryption allows:
- A.Faster decryption of data using optimized algorithms
- B.Only reading encrypted data without any modifications
- C.Computations on encrypted data without decrypting it✓ Correct
- D.Only writing encrypted data without reading it first
Explanation
Homomorphic encryption enables performing computations on ciphertext, producing encrypted results that match the plaintext computation.
Report an error in this question
Database SecurityHard
Q25. Database firewall works by:
- A.Encrypting all data stored in the database tables and log files
- B.Only blocking network traffic without inspecting SQL statements
- C.Creating physical firewalls around the database server hardware
- D.Monitoring SQL traffic and blocking unauthorized or suspicious queries✓ Correct
Explanation
A database firewall monitors SQL queries in real-time and blocks those that violate security policies.
Report an error in this question
Database SecurityHard
Q26. The k-anonymity privacy model ensures:
- A.Only k users can access the database at any given time during concurrent operations
- B.Data is stored in k copies across different sites for redundancy and availability
- C.All data is encrypted using a key of length k bits for secure storage and retrieval
- D.Each record is indistinguishable from at least k-1 other records on quasi-identifiers✓ Correct
Explanation
K-anonymity ensures that each record shares quasi-identifier values with at least k-1 other records to prevent re-identification.
Report an error in this question
Database SecurityHard
Q27. Differential privacy provides:
- A.Full access to all data without any restrictions or privacy controls
- B.Only physical security measures without any mathematical foundations
- C.No privacy guarantees of any kind for the data stored in the database
- D.Mathematical guarantees that query results do not reveal individual data✓ Correct
Explanation
Differential privacy adds controlled noise to query results to provide mathematical privacy guarantees for individuals.
Report an error in this question
Database SecurityHard
Q28. A privilege graph is used to:
- A.Track the flow of granted privileges among users✓ Correct
- B.Design ER diagrams for conceptual data modeling
- C.Optimize query execution plans for better speed
- D.Create indexes on columns for fast data retrieval
Explanation
A privilege graph shows how privileges flow from grantor to grantee, useful for cascade revocation analysis.
Report an error in this question
Database SecurityHard
Q29. Cascading revocation in SQL means:
- A.Revoking a privilege also revokes it from all users who received it through the original grant✓ Correct
- B.No revocation occurs and the privilege remains active for all users who currently have it
- C.Only the specified user loses the privilege and no other users are affected by the revocation
- D.All database privileges for every user are revoked regardless of the specific grant involved
Explanation
With CASCADE, revoking a privilege also revokes it from all users who received it transitively through that grant.
Report an error in this question
Database SecurityHard
Q30. Column-level encryption differs from TDE in that:
- A.It encrypts specific columns rather than entire database files✓ Correct
- B.It encrypts only at the network level rather than at storage level
- C.It encrypts only table names rather than the actual column data
- D.It is less secure than TDE because it covers fewer data elements
Explanation
Column-level encryption selectively encrypts individual columns containing sensitive data, while TDE encrypts entire database files.
Report an error in this question