Database security and backups

Last Updated :
Discuss
Comments

Question 1

You're administering a relational database that services an application. A developer writes a query in code like:

"SELECT * FROM Users WHERE username = '" + userInput + "' AND password = '" + passInput + "';"

What is the best focus to prevent exploitation of this kind of query?

  • A

    Enforce a strong-password policy on the Users table

  • B

    Use parameterised queries (or prepared statements) for the input

  • C

    Encrypt the Users table entirely so even if SQL runs it returns gibberish

  • D

    Disable the Users table access from the application layer

Question 2

A privilege review shows a junior user account has INSERT, UPDATE, and DELETE rights on nearly all tables in a production database, even though their job is simply to run reports (no data-modification needed). Which principle is being violated?

  • A

    Separation of duties

  • B

    Principle of least privilege

  • C

    Defense in depth

  • D

    Fail-safe defaults

Question 3

On a cloud-hosted database service, you notice that the database instance is listening directly on a public IP address and default port, accessible from the Internet (though authentication is required). What is the most appropriate next step among these?

  • A

    Change the password of the admin account immediately

  • B

    Turn on database-level encryption at rest

  • C

    Restrict network access so the database is only reachable from the application tier or private subnet

  • D

    Enable verbose logging so every connection is recorded

Question 4

You’re asked how to protect sensitive columns (e.g., credit-card numbers) inside your database. Which combination of methods provides the broadest protection?

  • A

    Encrypt the disk or volume hosting the database files and enforce strong passwords

  • B

    Encrypt data in transit (TLS) plus rely on role-based access control to restrict who can read the table

  • C

    Implement column-level encryption (or tokenisation) for the sensitive field, encrypt in transit, and restrict access to keys/supervisor roles

  • D

    Use views to hide the columns from most users and stop backups of those columns

Question 5

A database audit finds that the software hasn’t been patched for over one year. Which of the following risks is most directly implicated?

  • A

    Excessive user rights to the database

  • B

    Brute-force login attempts

  • C

    Known vulnerabilities in the database engine can be exploited by attackers

  • D

    Lack of backups and recovery testing

Question 6

You have enabled detailed logging of all database queries, including sensitive SELECTs, for forensic purposes. Which additional control makes this log-based monitoring most effective?

  • A

    Grant the DBA full rights to alter the logs so they can fix data quickly

  • B

    Encrypt the log files, store them on the same server as the database

  • C

    Send the logs to a remote, tamper-resistant server and monitor for anomalous activity

  • D

    Disable all user queries except during a fixed daily window

Question 7

Which of the following SQL statements correctly grants the ability for user ‘Alice’ on host ‘localhost’ to only SELECT and INSERT on table Orders in database SalesDB?

  • A

    GRANT ALL ON SalesDB.Orders TO 'Alice'@'localhost';

  • B

    GRANT SELECT, INSERT ON SalesDB.Orders TO 'Alice'@'localhost';

  • C

    GRANT SELECT ON SalesDB.* TO 'Alice'@'localhost';

  • D

    GRANT SELECT, INSERT, DELETE ON SalesDB.Orders TO 'Alice'@'localhost';

Question 8

An attacker successfully accesses a database user account that has only read-only permissions (SELECT). Which of the following controls would not mitigate the risk of data exfiltration in this scenario?

  • A

    Row-level filtering so sensitive rows are masked or hidden

  • B

    Limiting the number of rows returned by any single query

  • C

    Rotating encryption keys daily for data-at-rest

  • D

    Using network egress controls and data traffic analysis to detect large data dumps

Question 9

Bucket (or snapshot) backups of the database are made every hour, but no restore testing has ever been conducted and backup credentials are stored in the same server. Which dimension of the CIA triad (Confidentiality, Integrity, Availability) is most at risk here?

  • A

    Confidentiality

  • B

    Integrity

  • C

    Availability

  • D

    None — the backup process is sufficient

Question 10

In a production environment, you find that the database uses the default “root” (or “admin”) account with no multi-factor authentication, and that account is used for everyday queries. What’s the most urgent correction?

  • A

    Enable multi-factor authentication for all accounts, including root

  • B

    Remove the root account and rely only on regular users

  • C

    Change the name of the root account to something non-standard

  • D

    Create separate, least-privilege user accounts for every task and disable daily use of root

Tags:

There are 10 questions to complete.

Take a part in the ongoing discussion