| トピック | 出題範囲 |
|---|
| トピック 1 | - Manage Database Users: This section assesses the skills of Database Administrators in managing user accounts and authentication methods. It includes administering OS authentication, Kerberos authentication, PKI certificate authentication, and enterprise user security. Additionally, it covers identifying inactive accounts and managing secure passwords.
|
| トピック 2 | - Secure Passwords: This domain focuses on the importance of password security within database environments. It includes techniques for securing passwords in scripts and applications, changing user passwords securely, and administering external password stores.
|
| トピック 3 | - Assess Autonomous Database Self Securing: This final domain summarizes knowledge related to autonomous databases' self-securing capabilities. It emphasizes understanding how these features enhance overall database security without extensive manual intervention.
|
| トピック 4 | - Configure Network Security: This domain assesses the ability to manage network security settings. It involves assessing the need for network access control (ACL), managing ACLs for microservice deployments, configuring listener valid-node checking, and enhancing database communication security.
|
| トピック 5 | - Manage Database Security in the Cloud: This section evaluates skills related to cloud database security management. It involves assessing the shared responsibility model for cloud environments and managing hybrid cloud scenarios effectively.
|
| トピック 6 | - Assess Security Needs: This domain focuses on understanding the security requirements of a database environment. It involves evaluating risks, ensuring compliance with regulations, and identifying potential vulnerabilities to enhance overall security posture.
|
| トピック 7 | - Configure Fine Grained Access Control: This section focuses on implementing Fine Grained Access Control (FGAC) within databases. It includes configuring FGAC with Real Application Security, Virtual Private Database, and Oracle Label Security to ensure data access is appropriately controlled.
|
| トピック 8 | - Invoke the Database Security Assessment Tool: This section measures the ability to utilize the Database Security Assessment Tool effectively. It involves running assessments to identify security vulnerabilities within the database environment.
|
| トピック 9 | - Implement Data Masking and Data Redaction: This domain assesses skills in data masking and redaction techniques. It includes implementing data redaction strategies, using Enterprise Manager Data Masking Pack, performing sensitive data discovery, and automating masking operations.
|
| トピック 10 | - Configure and Manage Database Vault: This domain involves understanding and configuring Database Vault for enhanced security. It covers default separation of duties, configuring factors and rules, enforcing trusted path access, and performing operations control within Database Vault.
|
| トピック 11 | - Overview: This section measures the skills of Database Security Administrators and covers assessing security needs, including risk reduction and regulatory compliance. It emphasizes identifying typical attack points for databases and deploying a Maximum Security Architecture to safeguard data.
|
| トピック 12 | - Patch Databases: This domain focuses on maintaining database security through patch management. It includes assessing the need for CVE patches and understanding CVSS risk scoring to prioritize updates.
|
| トピック 13 | - Manage Authorization: This domain assesses skills related to authorization management. It includes administering system and object privileges, assigning administrative privileges, configuring secure application roles, and performing privilege analysis.
|