A database server for a financial application is scheduled for production deployment. Which of the following controls will BEST prevent tampering?
Correct Answer: B
The control that will best prevent tampering of a database server for a financial application is data validation.
Tampering is a type of attack or threat that involves modifying, altering, or changing the data or the information on a system or a network, such as a database server, without authorization or permission, and with malicious or harmful intent, such as fraud, corruption, or sabotage. Tampering can compromise the confidentiality, integrity, or availability of the data or the information, and can cause harm or damage to the system or the network, or to the organization or the business, or to the stakeholders or the customers.
Tampering can be prevented or mitigated by various controls or measures, such as:
* Service accounts removal: The control or the measure that involves deleting or disabling the service accounts, which are the accounts that are used or created for running or operating the services or the applications on a system or a network, such as a database server, and that have high or privileged access rights or permissions to the system or the network, or to the data or the information. Service accounts removal can prevent or mitigate tampering, as it can reduce or eliminate the unauthorized or unnecessary access or use of the service accounts, and as it can enhance the security or the protection of the system or the network, or of the data or the information.
* Data validation: The control or the measure that involves checking or verifying the data or the information that are entered or submitted to a system or a network, such as a database server, or to a service or an application, such as a financial application, using various methods, such as rules, formats, or ranges, to ensure or confirm that the data or the information are valid, accurate, or complete. Data validation can prevent or mitigate tampering, as it can detect or reject the invalid, inaccurate, or incomplete data or information, and as it can prevent or correct the modification, alteration, or change of the data or the information.
* Logging and monitoring: The control or the measure that involves recording or storing the information or the data about the activities, events, or issues that occur on a system or a network, such as a database server, or on a service or an application, such as a financial application, using various sources, such as the system, the application, the user, or the device, and observing or analyzing the information or the data, using various tools, techniques, or practices, such as alerts, reports, or audits. Logging and monitoring can prevent or mitigate tampering, as it can provide or generate the evidence or the trace of the tampering, and as it can enable or facilitate the response or the recovery of the tampering.
* Data sanitization: The control or the measure that involves removing or erasing the data or the information from a system or a network, such as a database server, or from a service or an application, such as a financial application, using various methods, such as deletion, overwriting, or destruction, to ensure or confirm that the data or the information are unrecoverable or inaccessible. Data sanitization can prevent or mitigate tampering, as it can eliminate or reduce the exposure or the vulnerability of the data or the information, and as it can protect or secure the data or the information from potential tampering. Data validation is the control that will best prevent tampering of a database server for a financial application, as it can provide the most direct or effective way of preventing or mitigating the tampering, and as it can ensure or enhance the quality, consistency, or reliability of the data or the information12. References: CISSP CBK, Fifth Edition, Chapter 3, page 245; CISSP Practice Exam - FREE 20 Questions and Answers, Question 15.