Database Security (CY-802 (A)) - Important Questions
-
Unit 57 Marks Medium Priority Asked: 2024
Why might traditional cryptographic algorithms be unsuitable for resource-constrained devices?
Direct extraction from May 2024 past paper (Unit 5, part a). Core question about lightweight cryptography suitability for constrained devices.
-
Unit 57 Marks Medium Priority Asked: 2024
Provide two reasons why traditional cryptographic algorithms might not be suitable for resource-constrained devices.
Direct extraction from May 2024 past paper (Unit 5, part b). Asks for two concrete reasons—typical short-answer 7-mark question.
-
Unit 55 Marks Medium Priority Asked: 2024
How might security threats for tiny devices differ from those for traditional computers?
Direct extraction from May 2024 past paper (Unit 5). Focuses on threat differences for tiny devices vs. traditional computers.
-
Unit 5 Low Priority Asked: 2024
In simple terms, why might standard encryption methods not be suitable for small devices (e.g., phones, sensors)?
Direct extraction from May 2024 past paper (Unit 5, short/simple prompt). Low-mark/zero-mark conceptual prompt included in source.
-
Unit 514 Marks High Priority
Explain the access control structures used in database systems. Describe discretionary access control (DAC), mandatory access control (MAC), and role-based access control (RBAC), and discuss how each is implemented in a relational DBMS with examples and trade-offs.
Core topic from Unit 5 (Access control structures). High-frequency topic in analytics heatmap; standard long-form exam question asking for explanation and examples of discretionary, mandatory and role-based access control in a DBMS.
-
Unit 510 Marks Medium Priority
Describe the Bell and LaPadula model and the Biba model. Compare their security goals and explain the kinds of database environments where each model is appropriate.
Standard theoretical question appearing in DB security syllabi: comparison of Bell-LaPadula and Biba integrity/confidentiality goals and applicability.
-
Unit 514 Marks Medium Priority
Explain the Database Security Lifecycle and illustrate each phase with examples of technical and administrative controls, and relevant metrics to measure effectiveness.
Comprehensive question on database security lifecycle — common long-answer/essay style in exams to test practical understanding of phases, controls and metrics.
-
Unit 510 Marks Medium Priority
List and explain common internal and external threats to a database system. For each threat provide at least one practical mitigation technique and briefly discuss implementation considerations.
Applied question: enumerating internal/external threats and proposing mitigations—frequently asked theme in unit assessments.
-
Unit 510 Marks Low Priority
Perform a simple data risk assessment for a confidential database: identify asset value, estimate likelihood and impact, and compute residual risk after applying an encryption control. Show calculations and justify assumptions.
Practical risk-assessment style question combining asset valuation and control effect; often used to test applied security engineering skills.
Quick Add to Notes
Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.
Create free accountHave an account? Log in
Notes Panel