| トピック | 出題範囲 |
|---|
| トピック 1 | - Configure Network Security: This domain assesses the ability to manage network security settings. It involves assessing the need for network access control (ACL), managing ACLs for microservice deployments, configuring listener valid-node checking, and enhancing database communication security.
|
| トピック 2 | - Configure and Use Auditing: This section measures skills in auditing practices within databases. It includes performing privileged user audits, configuring standard audits, fine-grained auditing, and utilizing unified auditing for comprehensive oversight.
|
| トピック 3 | - Configure and Use Contexts: This section measures the ability to use contexts effectively within a database. It covers understanding USERENV variables, client identifiers, extending unified auditing with context information, and utilizing context information with secure application roles.
|
| トピック 4 | - Patch Databases: This domain focuses on maintaining database security through patch management. It includes assessing the need for CVE patches and understanding CVSS risk scoring to prioritize updates.
|
| トピック 5 | - Manage Database Users: This section assesses the skills of Database Administrators in managing user accounts and authentication methods. It includes administering OS authentication, Kerberos authentication, PKI certificate authentication, and enterprise user security. Additionally, it covers identifying inactive accounts and managing secure passwords.
|
| トピック 6 | - Configure and Implement Encryption: This section focuses on encryption techniques to protect data. It includes encrypting data in motion and at rest using various methods such as native network encryption, TLS encryption, Transparent Database Encryption, and managing encryption keys.
|
| トピック 7 | - Configure and Manage Database Vault: This domain involves understanding and configuring Database Vault for enhanced security. It covers default separation of duties, configuring factors and rules, enforcing trusted path access, and performing operations control within Database Vault.
|
| トピック 8 | - Configure Fine Grained Access Control: This section focuses on implementing Fine Grained Access Control (FGAC) within databases. It includes configuring FGAC with Real Application Security, Virtual Private Database, and Oracle Label Security to ensure data access is appropriately controlled.
|
| トピック 9 | - Invoke the Database Security Assessment Tool: This section measures the ability to utilize the Database Security Assessment Tool effectively. It involves running assessments to identify security vulnerabilities within the database environment.
|
| トピック 10 | - Overview: This section measures the skills of Database Security Administrators and covers assessing security needs, including risk reduction and regulatory compliance. It emphasizes identifying typical attack points for databases and deploying a Maximum Security Architecture to safeguard data.
|
| トピック 11 | - Assess Security Needs: This domain focuses on understanding the security requirements of a database environment. It involves evaluating risks, ensuring compliance with regulations, and identifying potential vulnerabilities to enhance overall security posture.
|