Diagnostic Answers DS7-029–DS7-042
DS7-029 — A · pp. 228–229
Why: rights exceed legitimate job need = abuse of excessive privilege.
Distractors: Legitimate abuse misuses otherwise appropriate access; Elevation increases rights later; SQL injection is an input-channel attack.
Pair: Excessive vs Legitimate privilege abuse.
DS7-030 — B · pp. 229–230
Why: valid individual-record access used for unauthorized bulk purpose = legitimate-privilege abuse.
Distractors: not necessarily an over-grant; no default password or backup involved.
Pair: Legitimate abuse vs Excessive privilege.
DS7-031 — C · p. 230
Why: exploit converts ordinary access into admin access = Privilege elevation.
Distractors: not shared-account, patch-delay classification, or masking.
Pair: Elevation vs Excessive privilege.
DS7-032 — D · pp. 230–231
Why: Service = process/batch identity; Shared = generic human-used ID.
Distractors: A/B invent restrictions; C incorrectly equates distinct risks.
Pair: Service vs Shared account.
DS7-033 — A · pp. 231, 246–247
Why: IDS detects and notifies.
Distractors: IPS is automatic prevention/response; role hierarchy/CRUD are access-design artifacts.
Pair: IDS vs IPS.
DS7-034 — B · pp. 231–232
Why: attacker-supplied SQL statements enter a vulnerable data channel and execute as legitimate commands.
Distractors: A is social engineering; C worm behavior; D backup abuse.
Pair: SQL injection vs Phishing/Malware.
DS7-035 — C · pp. 232–233
Why: deceptive trusted-looking request for credentials = Phishing.
Distractors: Spyware monitors; Trojan hides malware; penetration test is authorized assessment.
Pair: Phishing vs Malware.
DS7-036 — D · pp. 234–235
Why: Virus depends on accompanying host file/program; Worm self-spreads across networks.
Distractors: A/B/C are false category distinctions.
Pair: Virus vs Worm.
DS7-037 — A · pp. 235–246
Why: Identify Requirements → Policy → Standards → Assess Risk → Implement Controls is the source activity sequence.
Distractors: B/C/D start with implementation/tools or skip core risk/classification logic.
Pair: Security activity sequence.
DS7-038 — B · pp. 235–236
Why: data-to-process and data-to-role matrices map touch points and needed permissions.
Distractors: scorecards/retention/topology do not express process-role data access needs.
Pair: Business requirements vs tool-only design.
DS7-039 — C · p. 236
Why: regulatory inventory should connect regulation, subject area, security-policy links, and implemented controls.
Distractors: A/B/D are incomplete lists that cannot operationalize compliance.
Pair: Regulatory inventory vs unlinked legal list.
DS7-040 — D · pp. 237–238
Why: a detailed measurable rule beneath a policy = Standard.
Distractors: Audit assesses; Entitlement is exposure; Risk classification is sensitivity.
Pair: Policy vs Standard.
DS7-041 — A · p. 238
Why: the Data Governance Council reviews/approves Data Security Policy in Chapter 7’s model.
Distractors: DBAs implement; auditors assess; users do not approve enterprise policy.
Pair: Policy approval vs operational ownership.
DS7-042 — B · pp. 239–240
Why: role groups reduce redundant individual grants and improve consistency at scale.
Distractors: ad-hoc permissions create inconsistency; shared accounts reduce accountability; monitoring does not justify broad access.
Pair: Role-based vs individual access.