Database Security (CY-802 (A)) - Important Questions
-
Unit 414 Marks High Priority
Describe the Bell–LaPadula and Biba integrity models. Compare their primary goals (confidentiality vs. integrity), explain the key rules of each model, and discuss where each model is most appropriate in database systems and the limitations when applied to modern DBMS implementations.
Aggregated core topic from Unit 4 (Bell and Biba frequently tested). Compare confidentiality and integrity models and their applicability to DBMS.
-
Unit 414 Marks High Priority
Explain user identification and authentication mechanisms used in database systems. Discuss password-based authentication, token-based authentication, biometric methods and multi-factor authentication. Describe techniques to secure authentication credentials (for example hashing with salts, secure storage, and secure transmission) and auditing of authentication events.
Core Unit 4 topic; highest frequency per analytics heatmap.
-
Unit 410 Marks Low Priority
Explain the Database Security Lifecycle and illustrate each phase with examples of technical, administrative and physical controls and at least one metric that can be used to measure effectiveness in each phase.
Core conceptual question recommended by aggregated analytics for exam-style answers.
-
Unit 410 Marks Low Priority
List and explain common internal and external database threats (for example insider abuse, SQL injection, privilege escalation, malware, physical theft). For each threat propose at least one practical mitigation technique and identify which phase(s) of the Database Security Lifecycle the mitigation belongs to.
Common exam-style question testing threat analysis skills relevant to Unit 4.
-
Unit 414 Marks Low Priority
Explain how access control structures — discretionary access control (DAC), mandatory access control (MAC), and role-based access control (RBAC) — are implemented in a relational DBMS. For each model describe the main components, how policies are expressed and enforced, and discuss trade-offs in terms of administration, granularity, and security.
Implementation-focused question linking access control theory to RDBMS practice; typical long-answer question.
-
Unit 47 Marks Low Priority
Perform a simple data risk assessment for a database asset: identify asset value, estimate likelihood and impact, compute the baseline risk, then compute the residual risk after applying an encryption control with a given effectiveness. Use the standard risk formulas below and show calculations.
$$Risk = Likelihood \times Impact$$
$$Residual\ Risk = Risk \times \left(1 - Control\ Effectiveness\right)$$
Applied quantitative question (risk calculation uses standard risk formulas).
-
Unit 47 Marks Medium Priority Asked: 2024
Describe the purpose of a cryptographic hash function. Provide an example of a real-world application that utilizes lightweight hashing.
Direct extraction from raw past-paper data (May 2024).
Quick Add to Notes
Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.
Create free accountHave an account? Log in
Notes Panel