All Exams Test series for 1 year @ ₹349 only
Question

Which one of the following is considered as a threat to database and DBMS ?

The correct answer is Unauthorised access

Understanding Database Threats and DBMS Security

Databases and Database Management Systems (DBMS) are critical assets for any organization, storing valuable information. Protecting this data from various threats is paramount. A threat, in the context of database security, refers to any potential danger that could exploit a vulnerability and compromise the confidentiality, integrity, or availability of the database system or the data it holds.

Analyzing the Options for Database Threats

Let's examine the given options to determine which one represents a significant threat to databases and DBMS:

  • Firewalls: Firewalls are network security devices designed to monitor and control incoming and outgoing network traffic based on predetermined security rules. They act as a barrier to prevent unauthorized access to systems, including databases. Therefore, firewalls are a defense mechanism, not a threat themselves.
  • Insertion of viruses: Viruses are malicious software programs that can replicate themselves and spread to other systems. They can cause harm by corrupting data, deleting files, or disrupting system operations. Inserting viruses into a system that hosts a database or DBMS can certainly pose a threat, potentially compromising the integrity and availability of the database.
  • Unauthorised access: This refers to accessing a database or DBMS without proper permission or authentication. Unauthorised access is a major security threat because it can lead to data breaches, modification of data, deletion of information, or denial of service. Gaining unauthorised access is often the first step in many cyberattacks targeting databases.
  • Log of system failures: System failure logs are records that track errors, crashes, and other system malfunctions. These logs are useful for diagnosing problems and troubleshooting. They are historical records of events, not threats themselves. While analyzing logs might reveal past security incidents or vulnerabilities, the log itself is not the threat.

Why Unauthorised Access is a Major Database Threat

Among the given options, unauthorised access is universally recognized as a fundamental and severe threat to database security. It directly targets the core security principles:

  • Confidentiality: Unauthorised users can view sensitive data they are not permitted to see.
  • Integrity: Unauthorised users might alter or delete data, corrupting its accuracy and reliability.
  • Availability: Unauthorised actions could potentially disrupt access for legitimate users or even make the database unavailable.

While viruses are also a threat, unauthorised access is often the enabler for other malicious activities, including the potential insertion of viruses or other malware into the system.

Conclusion on Database and DBMS Threats

Based on the analysis, unauthorised access is a direct and significant threat to databases and DBMS, potentially compromising confidentiality, integrity, and availability. Other options like viruses are also threats, but firewalls are defenses, and system logs are records.

The correct answer identifies unauthorised access as a key threat.

Option Nature Threat to Database/DBMS? Explanation
Firewalls Security Mechanism No Protects against threats like unauthorised access.
Insertion of viruses Malware Yes (Potential) Can compromise system integrity/availability; often requires initial unauthorised access.
Unauthorised access Security Breach Event Yes (Significant) Directly compromises confidentiality, integrity, and availability.
Log of system failures Record/Diagnostic Tool No A record of past events, not a threat itself.

Revision Table: Key Database Security Concepts

Term Definition Relevance to Security
Threat A potential danger that could exploit a vulnerability. Something to defend against.
Vulnerability A weakness in the system that can be exploited. Needs to be identified and fixed.
Attack An action taken to exploit a vulnerability. The event that compromises security.
Countermeasure A security control to reduce risk. Implemented to defend against threats.
Risk The potential for loss or damage when a threat exploits a vulnerability. Needs to be assessed and managed.

Additional Information on Database Threats

Besides unauthorised access and malware (like viruses), databases face numerous other threats, including:

  • SQL Injection Attacks: Injecting malicious SQL code into input fields to manipulate the database.
  • Denial of Service (DoS) Attacks: Overwhelming the database system to make it unavailable to legitimate users.
  • Privilege Abuse: Legitimate users exceeding or misusing their granted permissions.
  • Data Leakage: Unintentional exposure of sensitive data.
  • Backup Media Theft: Physical theft of backup tapes or drives containing database copies.
  • Weak Authentication/Authorization: Poor password policies, lack of multi-factor authentication, or incorrectly configured access controls.

Robust database security involves implementing multiple layers of defense, including strong authentication, granular authorization, encryption, regular patching, security monitoring, and employee training.

Was this answer helpful?

Important Questions from Database Introduction

  1. Which type of storage device is a hard disk?

  2. Deductive model of DBMS is also known as ______.

  3. _____ is a system database that contains description of the data in the database.

  4. What is DBMS?

  5. Which of the following is an advantage of ‘server-database’?

Need Expert Advice?

Start Your Preparation with Prepp Mobile App

Download the app from Google Play & App Store
Download the app from Google Play & App Store
Prepp Mobile App