フリー問題

Developing AI-Enabled Database Solutions (DP-800) のフリー問題 9 / 20 問目

問題文

A database role was granted SELECT on a schema. One member of that role must be blocked from reading one table in that schema, permanently, even if someone later grants that person SELECT directly. Which statement is correct?

選択肢

  1. Grant a column-level permission on the other columns, because the column is the finest granularity object permissions can be given at, and a GRANT on a column always overrides a DENY on the table.
  2. Remove the user from the role, because object-level permissions cannot be denied to an individual user.
  3. Issue DENY on that table to that user, because a blocking DENY causes the permission check to fail regardless of any GRANT collected.
  4. Issue REVOKE on that table to that user, because revoking removes the permission and prevents future grants.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。