ITPEC IP October 2019 Question 20

Source exam: ITPEC IP October 2019Topic: Databases

ITPEC IP October 2019 — Question 20 of 100

Access rights should be assigned according to both the user and the data required for that user's work. Authorization rules can limit which tables, rows, columns, views, or operations each role may access while preserving a single controlled database.

Answer (a)

Why not others:
- distributing separate database copies creates synchronization and security problems

- fixed user-specific columns cannot express every row, action, or changing responsibility

- passwords on individual records are difficult to manage and are not a normal authorization model

Key rule: Apply least privilege through centralized user or role permissions so each person sees and changes only the data needed for assigned duties.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.