問題文
A database role was granted SELECT on a schema. One member of that role must be blocked from reading one table in that schema, permanently, even if someone later grants that person SELECT directly. Which statement is correct?
選択肢
- Grant a column-level permission on the other columns, because the column is the finest granularity object permissions can be given at, and a GRANT on a column always overrides a DENY on the table.
- Remove the user from the role, because object-level permissions cannot be denied to an individual user.
- Issue DENY on that table to that user, because a blocking DENY causes the permission check to fail regardless of any GRANT collected.
- Issue REVOKE on that table to that user, because revoking removes the permission and prevents future grants.