Question 1
You're administering a relational database that services an application. A developer writes a query in code like:
"SELECT * FROM Users WHERE username = '" + userInput + "' AND password = '" + passInput + "';"What is the best focus to prevent exploitation of this kind of query?
Enforce a strong-password policy on the Users table
Use parameterised queries (or prepared statements) for the input
Encrypt the Users table entirely so even if SQL runs it returns gibberish
Disable the Users table access from the application layer
Question 2
A privilege review shows a junior user account has INSERT, UPDATE, and DELETE rights on nearly all tables in a production database, even though their job is simply to run reports (no data-modification needed). Which principle is being violated?
Separation of duties
Principle of least privilege
Defense in depth
Fail-safe defaults
Question 3
On a cloud-hosted database service, you notice that the database instance is listening directly on a public IP address and default port, accessible from the Internet (though authentication is required). What is the most appropriate next step among these?
Change the password of the admin account immediately
Turn on database-level encryption at rest
Restrict network access so the database is only reachable from the application tier or private subnet
Enable verbose logging so every connection is recorded
Question 4
You’re asked how to protect sensitive columns (e.g., credit-card numbers) inside your database. Which combination of methods provides the broadest protection?
Encrypt the disk or volume hosting the database files and enforce strong passwords
Encrypt data in transit (TLS) plus rely on role-based access control to restrict who can read the table
Implement column-level encryption (or tokenisation) for the sensitive field, encrypt in transit, and restrict access to keys/supervisor roles
Use views to hide the columns from most users and stop backups of those columns
Question 5
A database audit finds that the software hasn’t been patched for over one year. Which of the following risks is most directly implicated?
Excessive user rights to the database
Brute-force login attempts
Known vulnerabilities in the database engine can be exploited by attackers
Lack of backups and recovery testing
Question 6
You have enabled detailed logging of all database queries, including sensitive SELECTs, for forensic purposes. Which additional control makes this log-based monitoring most effective?
Grant the DBA full rights to alter the logs so they can fix data quickly
Encrypt the log files, store them on the same server as the database
Send the logs to a remote, tamper-resistant server and monitor for anomalous activity
Disable all user queries except during a fixed daily window
Question 7
Which of the following SQL statements correctly grants the ability for user ‘Alice’ on host ‘localhost’ to only SELECT and INSERT on table Orders in database SalesDB?
GRANT ALL ON SalesDB.Orders TO 'Alice'@'localhost';
GRANT SELECT, INSERT ON SalesDB.Orders TO 'Alice'@'localhost';
GRANT SELECT ON SalesDB.* TO 'Alice'@'localhost';
GRANT SELECT, INSERT, DELETE ON SalesDB.Orders TO 'Alice'@'localhost';
Question 8
An attacker successfully accesses a database user account that has only read-only permissions (SELECT). Which of the following controls would not mitigate the risk of data exfiltration in this scenario?
Row-level filtering so sensitive rows are masked or hidden
Limiting the number of rows returned by any single query
Rotating encryption keys daily for data-at-rest
Using network egress controls and data traffic analysis to detect large data dumps
Question 9
Bucket (or snapshot) backups of the database are made every hour, but no restore testing has ever been conducted and backup credentials are stored in the same server. Which dimension of the CIA triad (Confidentiality, Integrity, Availability) is most at risk here?
Confidentiality
Integrity
Availability
None — the backup process is sufficient
Question 10
In a production environment, you find that the database uses the default “root” (or “admin”) account with no multi-factor authentication, and that account is used for everyday queries. What’s the most urgent correction?
Enable multi-factor authentication for all accounts, including root
Remove the root account and rely only on regular users
Change the name of the root account to something non-standard
Create separate, least-privilege user accounts for every task and disable daily use of root
There are 10 questions to complete.