OCP-042 fine-grained Auditing

本文介绍了一种银行用于跟踪高额账户余额访问并发送警告的方法——细粒度审计。通过定义特定条件来精确监控数据访问行为,并利用事件处理器进一步处理审计事件。

13. The SAVE_AMT column in the ACCOUNTS table contains the balance details of customers in a bank.
As part of the yearend
tax and interest calculation process, all the rows in the table need to be accessed.
The bank authorities want to track access to the rows containing balance amounts exceeding $200,000,
and then send an alert message to the administrator.
Which method would you suggest to the bank for achieving this task?
A. implementing valuebased
auditing by using triggers
B. implementing finegrained
auditing with audit condition and event handler
C. performing standard database auditing to audit object privileges by setting the AUDIT_TRAIL
parameter to EXTENDED
D. performing standard database auditing to audit SQL statements with granularity level set to ACCESS
Answer: B



Fine-Grained Auditing

Fine-grained auditing allows the monitoring of data access based on content. It provides granular auditing of queries, as well as INSERTUPDATE, and DELETEoperations. For example, a central tax authority needs to track access to tax returns to guard against employee snooping, with enough detail to determine what data was accessed. It is not enough to know that SELECT privilege was used by a specific user on a particular table. Fine-grained auditing provides this deeper functionality.

In general, fine-grained auditing policy is based on simple user-defined SQL predicates on table objects as conditions for selective auditing. During fetching, whenever policy conditions are met for a returning row, the query is audited. Later, Oracle runs user-defined audit event handlers using autonomous transactions to process the event.

Fine-grained auditing can be implemented in user applications using the DBMS_FGA package or by using database triggers.




评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值