Skip to content
CY-802 (A) · Database Security/Important Questions

Database Security (CY-802 (A)) - Important Questions

  1. Unit 314 Marks High Priority

    List and explain common internal and external database threats. For each threat propose at least one mitigation technique.

    Core Unit 3 topic; frequently tested. Directly addresses identification and mitigation of threats.

  2. Unit 310 Marks High Priority

    Describe Bell and LaPadula and Biba models. Compare their goals and explain where each is appropriate in database systems.

    Fundamental confidentiality and integrity models for database systems; commonly required for comparisons and applicability.

  3. Unit 310 Marks High Priority

    Explain how access control structures (discretionary, mandatory, role-based) are implemented in a relational DBMS and discuss trade-offs.

    Practical implementation question covering discretionary, mandatory and role-based access control in RDBMS; high exam value.

  4. Unit 37 Marks Medium Priority

    Explain the Database Security Lifecycle and illustrate each phase with examples of controls and metrics.

    Management-level topic assessing understanding of planning, implementation and measurement of database security controls.

  5. Unit 310 Marks Medium Priority

    Perform a simple data risk assessment: identify asset value, likelihood, impact and compute residual risk after applying an encryption control.

    Applied question combining asset valuation, likelihood and control effectiveness; tests practical risk computation and reasoning.

  6. Unit 314 Marks Medium Priority

    List the common methods attackers use for external attacks on database servers (for example, SQL injection, buffer overflow, OS privilege escalation). For each method describe detection techniques and mitigation strategies.

    Technical details on attack vectors and defences; useful for both theory and practical viva or long-answer questions.

  7. Unit 37 Marks Medium Priority

    Explain internal (insider) threats to databases. Describe techniques to detect insider threats and procedures to limit damage once an insider compromise is discovered.

    Insider threat focus: identification, motivations, detection mechanisms and response — a crucial Unit 3 subtopic.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in