Click Study Flashcards above to open the flashcard hub — hundreds of DataSys+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official DS0-001 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CompTIA DataSys+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.
DataSys+ Flashcard Study Modes
Flip mode is for first passes, where you read a front like Deadlock and check yourself against the back. Match turns short pairings such as RPO into a timed term-to-definition game. Type shows the definition and makes you produce the term from memory, which exposes shaky acronyms fast. Quiz builds multiple-choice items from the same 282 cards for mixed review.

Why Flashcards Work for the DataSys+
Database Management and Maintenance carries the heaviest official weight at 25% and holds 52 cards on day-to-day operations. Concurrency and performance vocabulary shows up in fronts such as Locking, Deadlock and Blocking, while upkeep and scaling terms come through Patching, Sharding and Archiving. Table scan sits with the performance group.
Database Fundamentals is weighted at 24% and is the largest block in the deck with 86 cards. The SQL language categories appear as DDL, DML and DCL, transaction handling is covered by the card for TCL, and design vocabulary runs through fronts like ERD, ACID and BCNF, with Heap covering physical storage.
Data and Database Security is weighted at 23% across 52 cards. Encryption and transport protection appear through TDE, TLS and AES, identity and authorization through MFA and RBAC, and data handling obligations through PII and GDPR. The card for Salt ties back to how stored credentials are protected.
Database Deployment holds 16% of the exam and 44 cards. Data movement is drilled through ETL and ELT, workload types through OLTP and OLAP, and hosting models through IaaS, PaaS and DBaaS. Format-level fronts such as CSV round out the ingestion side of the domain.
Business Continuity is weighted at 12% but still brings 48 cards, so the ratio favors you. Recovery targets and service terms appear as RPO, RTO and SLA, reliability math through MTTR and MTBF, and redundancy through RAID 0, RAID 1 and RAID 5.
The DataSys+ is dense with things you simply have to know cold — SQL command categories, join types, the normal forms, ACID, RAID levels, and security acronyms.[1] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
DataSys+ Flashcards by Domain
The cards are organized by the five official DS0-001 domains. Drill the highest-weighted ones first — Database Management & Maintenance and Database Fundamentals make up nearly half the exam:[1]
| Domain | Exam weight |
|---|---|
| Database Management and Maintenance | 25% |
| Database Fundamentals | 24% |
| Data and Database Security | 23% |
| Database Deployment | 16% |
| Business Continuity | 12% |
How to Get the Most Out of These Flashcards
- Open with the heaviest domain. Database Management and Maintenance is 25% of the exam across 52 cards, and its Locking and Blocking vocabulary keeps reappearing in security and deployment questions.
- Type-drill the acronyms you only half know. Fronts like TDE and RPO are easy to recognize in Flip mode but hard to produce cold, which is exactly what Type mode forces.
- Use Match on near-identical families. The RAID 0, RAID 1 and RAID 5 cards blur together under time pressure, and a timed pairing round makes the distinctions stick better than rereading.
- Move to the practice test once Quiz feels easy. When mixed multiple choice on Database Fundamentals stops surprising you, switch to full-length questions and use the study guide for gaps the cards expose.
- Work one domain per sitting. With 282 cards, cycling through Database Deployment or Business Continuity in a single session and rotating domains beats grinding the whole deck in one pass.
DataSys+ Flashcards FAQ
Hundreds of free DataSys+ flashcards, organized across all five DS0-001 domains — Database Fundamentals, Database Deployment, Database Management and Maintenance, Data and Database Security, and Business Continuity. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the DataSys+'s heavy memorization load: SQL commands, join types, normal forms, RAID levels, and security terms.
All five DS0-001 domains: Database Fundamentals (SQL, keys, joins, normalization, ACID), Database Deployment (models, environments, OLTP/OLAP), Database Management and Maintenance (indexing, performance, concurrency), Data and Database Security (access control, encryption, threats), and Business Continuity (backups, RAID, disaster recovery).
Lead with the heaviest domains — Database Management & Maintenance (25%) and Database Fundamentals (24%). Drill the SQL command categories and join types with Type and Quiz modes until automatic, then mix in the other domains. Pair the cards with our full practice test before exam day.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current CompTIA DataSys+ DS0-001 exam objectives, covering all five scored domains in their official proportions. DataSys+ is the database-administration certification, distinct from CompTIA Data+ (analytics).
DataSys+ flashcard bank
All 282 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Database Fundamentals (86)
- ACID
Show answerHide answer
Atomicity, Consistency, Isolation, Durability — the four guarantees of a reliable database transaction.
- Atomicity (ACID)
Show answerHide answer
A transaction completes fully or not at all — partial changes are rolled back.
- Consistency (ACID)
Show answerHide answer
A transaction moves the database from one valid state to another, honoring all constraints.
- Isolation (ACID)
Show answerHide answer
Concurrent transactions don't interfere; each behaves as if it ran alone.
- Durability (ACID)
Show answerHide answer
Once committed, changes survive crashes and power loss (persisted to non-volatile storage).
- Relational database
Show answerHide answer
Stores data in tables (relations) of rows and columns with a defined schema; queried with SQL.
- Primary key
Show answerHide answer
A column (or set) that uniquely identifies each row; cannot be null or duplicated.
- Foreign key
Show answerHide answer
A column that references another table's primary key, enforcing referential integrity.
- Composite key
Show answerHide answer
A primary key made up of two or more columns combined.
- Candidate key
Show answerHide answer
Any column or set of columns that could serve as the primary key (uniquely identifies a row).
- Surrogate key
Show answerHide answer
An artificial, system-generated key (e.g., auto-increment id) used instead of natural data.
- Natural key
Show answerHide answer
A key made from real, meaningful data that already exists (e.g., email or SSN).
- Referential integrity
Show answerHide answer
The rule that every foreign-key value must match an existing primary-key value (no orphans).
- Entity integrity
Show answerHide answer
The rule that every table has a primary key and no primary-key value is null.
- Schema
Show answerHide answer
The structure/blueprint of a database: tables, columns, data types, keys, and relationships.
- Tuple / row
Show answerHide answer
A single record in a table — one set of related values across all columns.
- Attribute / column
Show answerHide answer
A named field in a table holding one type of value for every row.
- Cardinality
Show answerHide answer
The nature of a relationship between tables: one-to-one, one-to-many, or many-to-many.
- Normalization
Show answerHide answer
Organizing tables to reduce redundancy and avoid update/insert/delete anomalies.
- First Normal Form (1NF)
Show answerHide answer
Each cell holds a single atomic value; no repeating groups; each row is unique.
- Second Normal Form (2NF)
Show answerHide answer
1NF and every non-key column depends on the whole primary key (no partial dependencies).
- Third Normal Form (3NF)
Show answerHide answer
2NF and no non-key column depends on another non-key column (no transitive dependencies).
- BCNF
Show answerHide answer
Boyce-Codd Normal Form — a stricter 3NF where every determinant is a candidate key.
- Denormalization
Show answerHide answer
Deliberately adding redundancy to speed up read-heavy queries, trading off integrity.
- DDL
Show answerHide answer
Data Definition Language — CREATE, ALTER, DROP, TRUNCATE; defines and changes structure.
- DML
Show answerHide answer
Data Manipulation Language — SELECT, INSERT, UPDATE, DELETE; reads and changes data.
- DCL
Show answerHide answer
Data Control Language — GRANT and REVOKE; controls permissions.
- TCL
Show answerHide answer
Transaction Control Language — COMMIT, ROLLBACK, SAVEPOINT; manages transactions.
- SELECT
Show answerHide answer
DML statement that retrieves rows from one or more tables.
- INSERT
Show answerHide answer
DML statement that adds a new row to a table.
- UPDATE
Show answerHide answer
DML statement that modifies existing rows that match a condition.
- DELETE
Show answerHide answer
DML statement that removes rows matching a WHERE clause; can be rolled back.
- TRUNCATE
Show answerHide answer
DDL statement that removes all rows from a table quickly and resets it.
- DROP
Show answerHide answer
DDL statement that removes an entire table (structure and data) from the database.
- WHERE clause
Show answerHide answer
Filters rows in a query to those that meet a condition.
- GROUP BY
Show answerHide answer
Groups rows that share values so aggregate functions apply per group.
- HAVING clause
Show answerHide answer
Filters groups after GROUP BY (WHERE filters rows before grouping).
- ORDER BY
Show answerHide answer
Sorts the result set by one or more columns, ascending or descending.
- DISTINCT
Show answerHide answer
Removes duplicate rows from a SELECT result set.
- INNER JOIN
Show answerHide answer
Returns only rows with matching values in both joined tables.
- LEFT JOIN
Show answerHide answer
Returns all rows from the left table plus matches from the right (NULLs where none).
- RIGHT JOIN
Show answerHide answer
Returns all rows from the right table plus matches from the left (NULLs where none).
- FULL OUTER JOIN
Show answerHide answer
Returns all rows from both tables, with NULLs where either side has no match.
- CROSS JOIN
Show answerHide answer
Returns the Cartesian product — every row of one table paired with every row of the other.
- SELF JOIN
Show answerHide answer
A table joined to itself, often to compare rows within the same table.
- Aggregate function
Show answerHide answer
Computes a single value over a set of rows: COUNT, SUM, AVG, MIN, MAX.
- COUNT()
Show answerHide answer
Aggregate function returning the number of rows (or non-null values).
- View
Show answerHide answer
A saved, named query that acts like a virtual table; simplifies access and can restrict columns.
- Index
Show answerHide answer
A structure that speeds row lookups by a column's value without scanning the whole table.
- Data redundancy
Show answerHide answer
The same data stored in more than one place — a source of inconsistency normalization reduces.
- NULL
Show answerHide answer
A marker for a missing or unknown value — not zero and not an empty string.
- Constraint
Show answerHide answer
A rule enforced on a column: PRIMARY KEY, FOREIGN KEY, UNIQUE, NOT NULL, CHECK, DEFAULT.
- UNIQUE constraint
Show answerHide answer
Ensures all values in a column (or set) are different across rows.
- CHECK constraint
Show answerHide answer
Restricts column values to those that satisfy a boolean condition.
- Data type
Show answerHide answer
Defines the kind of value a column stores: INT, VARCHAR, DATE, DECIMAL, BOOLEAN, etc.
- VARCHAR vs CHAR
Show answerHide answer
VARCHAR stores variable-length text; CHAR is fixed-length and padded.
- SQL vs NoSQL
Show answerHide answer
SQL = structured, fixed-schema relational tables; NoSQL = flexible schema, horizontal scale.
- Document database
Show answerHide answer
NoSQL store of self-describing documents (e.g., JSON) — example: MongoDB.
- Key-value store
Show answerHide answer
NoSQL store mapping unique keys to values — example: Redis.
- Column-family store
Show answerHide answer
NoSQL store organizing data by column families for wide rows — example: Cassandra.
- Graph database
Show answerHide answer
NoSQL store of nodes and relationships — example: Neo4j.
- ERD
Show answerHide answer
Entity-Relationship Diagram — a model of entities, attributes, and relationships in a design.
- DBMS
Show answerHide answer
Database Management System — software that stores, retrieves, and manages databases.
- Stored procedure
Show answerHide answer
A named, precompiled set of SQL statements executed by name, often with parameters.
- Trigger
Show answerHide answer
Code that runs automatically in response to an INSERT, UPDATE, or DELETE event.
- Function (SQL)
Show answerHide answer
A routine that returns a value and can be used inside a query.
- LIKE operator
Show answerHide answer
Pattern-matches text in a WHERE clause using wildcards % (any string) and _ (one char).
- IN operator
Show answerHide answer
Tests whether a value matches any value in a list or subquery.
- BETWEEN operator
Show answerHide answer
Tests whether a value falls within an inclusive range.
- Subquery
Show answerHide answer
A query nested inside another query, used in SELECT, FROM, or WHERE.
- UNION
Show answerHide answer
Combines result sets of two queries and removes duplicates (UNION ALL keeps them).
- Alias (AS)
Show answerHide answer
A temporary name given to a column or table in a query for readability.
- COALESCE
Show answerHide answer
Returns the first non-null value from a list of expressions.
- CASE expression
Show answerHide answer
Adds if/then/else conditional logic inside a SQL query.
- Transaction
Show answerHide answer
A unit of work treated as a single, all-or-nothing operation.
- COMMIT
Show answerHide answer
Permanently saves the changes made in the current transaction.
- ROLLBACK
Show answerHide answer
Undoes the changes made in the current transaction.
- SAVEPOINT
Show answerHide answer
A marker within a transaction you can roll back to without undoing everything.
- One-to-many relationship
Show answerHide answer
One row in a table relates to many rows in another (the most common relationship).
- Many-to-many relationship
Show answerHide answer
Rows on both sides relate to many — implemented with a junction (bridge) table.
- Junction table
Show answerHide answer
A bridge table that resolves a many-to-many relationship using two foreign keys.
- Domain (column)
Show answerHide answer
The set of valid values a column may hold, enforced by data type and constraints.
- Heap
Show answerHide answer
A table with no clustered index — rows stored in no particular order.
- Auto-increment / identity
Show answerHide answer
A column that automatically assigns the next sequential number to new rows.
- Temporal data
Show answerHide answer
Time-based data; some databases support system-versioned (temporal) tables for history.
- JSON column
Show answerHide answer
A column storing JSON documents, blending relational and document storage.
Database Deployment (44)
- OLTP
Show answerHide answer
Online Transaction Processing — many short real-time transactions; normalized for fast writes.
- OLAP
Show answerHide answer
Online Analytical Processing — complex analytical queries over large historical data; often denormalized.
- ETL
Show answerHide answer
Extract, Transform, Load — moves and reshapes data from sources into a warehouse.
- ELT
Show answerHide answer
Extract, Load, Transform — loads raw data first, then transforms it in the target system.
- Data warehouse
Show answerHide answer
A central repository of integrated historical data optimized for analysis and reporting.
- Data lake
Show answerHide answer
A store of raw data in native format at scale, for varied later processing.
- Data mart
Show answerHide answer
A subject-focused subset of a data warehouse for a specific team or use.
- Star schema
Show answerHide answer
A warehouse design: one central fact table linked to denormalized dimension tables.
- Snowflake schema
Show answerHide answer
A star schema whose dimension tables are normalized into related sub-tables.
- Fact table
Show answerHide answer
The central table in a warehouse holding measurable, numeric business events.
- Dimension table
Show answerHide answer
A table of descriptive attributes (who, what, where, when) joined to facts.
- Database deployment
Show answerHide answer
Installing, configuring, and making a database available in an environment.
- Configuration baseline
Show answerHide answer
A documented standard config used to deploy databases consistently and securely.
- Infrastructure as code (IaC)
Show answerHide answer
Managing infrastructure and config as version-controlled files (e.g., Terraform, Ansible).
- Database migration
Show answerHide answer
Moving a database or its data/schema to a new version, server, or platform.
- Schema migration
Show answerHide answer
Applying versioned, repeatable changes to a database structure over time.
- On-premises database
Show answerHide answer
A database running on hardware the organization owns and manages itself.
- Cloud database
Show answerHide answer
A database hosted/managed in a cloud provider's environment (IaaS, PaaS, or DBaaS).
- DBaaS
Show answerHide answer
Database as a Service — a fully managed cloud database (provider handles patching, backups, HA).
- IaaS
Show answerHide answer
Infrastructure as a Service — you manage the OS and DBMS on provider-supplied VMs.
- PaaS
Show answerHide answer
Platform as a Service — the provider manages the platform; you deploy databases/apps on it.
- Scripting fundamentals
Show answerHide answer
Using shell/Python/PowerShell + SQL scripts to automate deployment and admin tasks.
- Idempotent script
Show answerHide answer
A script that produces the same result no matter how many times it runs.
- Connection string
Show answerHide answer
Parameters an app uses to connect: server, database, credentials, and options.
- ODBC / JDBC
Show answerHide answer
Standard APIs/drivers that let applications connect to and query databases.
- Containerized database
Show answerHide answer
A database packaged in a container (e.g., Docker) for portable, repeatable deployment.
- Staging environment
Show answerHide answer
A production-like environment for testing deployments before go-live.
- Sandbox / dev environment
Show answerHide answer
An isolated environment for development and experimentation, separate from production.
- Version control (DB)
Show answerHide answer
Tracking schema and script changes in a repository (e.g., Git) for review and rollback.
- Data import/export
Show answerHide answer
Bulk loading or extracting data via tools like BCP, COPY, or import/export utilities.
- CSV
Show answerHide answer
Comma-Separated Values — a plain-text format commonly used to import/export tabular data.
- Database instance
Show answerHide answer
A running copy of the DBMS engine managing one or more databases in memory and on disk.
- Blue-green deployment
Show answerHide answer
Two identical environments; switch traffic to the new one for zero-downtime releases.
- Rollback (deployment)
Show answerHide answer
Reverting a deployment to the previous known-good version after a failure.
- Smoke test
Show answerHide answer
A quick post-deployment check that core functionality works.
- Bulk insert
Show answerHide answer
Loading many rows at once efficiently, bypassing row-by-row overhead.
- Data transformation
Show answerHide answer
Cleaning, reshaping, and converting data during ETL/ELT.
- Data validation (load)
Show answerHide answer
Verifying imported data meets type, range, and integrity rules.
- Connection encryption
Show answerHide answer
Requiring TLS for client-server connections during deployment hardening.
- Environment variable
Show answerHide answer
A configuration value (e.g., credentials, host) supplied to a deployment at runtime.
- Secrets management
Show answerHide answer
Storing credentials/keys securely (vaults) rather than hard-coded in scripts.
- Database link / linked server
Show answerHide answer
A configured connection that lets one database query another remote database.
- Replication setup
Show answerHide answer
Configuring primary and replica roles during deployment for HA or read scaling.
- Capacity sizing
Show answerHide answer
Estimating CPU, memory, and storage before deploying a database.
Database Management and Maintenance (52)
- Clustered index
Show answerHide answer
Defines the physical sort order of a table's rows; only one per table.
- Non-clustered index
Show answerHide answer
A separate structure pointing back to rows; many allowed per table.
- Composite index
Show answerHide answer
An index on two or more columns, useful for multi-column lookups and sorting.
- B-tree index
Show answerHide answer
A balanced-tree structure that keeps lookups fast as data grows.
- Covering index
Show answerHide answer
An index that contains all columns a query needs, so the table isn't read.
- Index fragmentation
Show answerHide answer
Disordered index pages that slow reads; fixed by rebuilding or reorganizing.
- Index rebuild
Show answerHide answer
Recreates an index to remove fragmentation (heavier than a reorganize).
- Index reorganize
Show answerHide answer
Defragments index pages in place with lower overhead than a rebuild.
- Statistics (DB)
Show answerHide answer
Metadata about data distribution the optimizer uses to choose a good plan.
- Query optimizer
Show answerHide answer
The DBMS component that chooses the execution strategy for a SQL statement.
- Execution plan
Show answerHide answer
The optimizer's step-by-step plan for running a query (scans, seeks, joins, sorts).
- Table scan
Show answerHide answer
Reading every row of a table — slow on large tables; a sign a useful index is missing.
- Index seek
Show answerHide answer
Using an index to jump directly to matching rows — efficient lookup.
- Performance tuning
Show answerHide answer
Improving speed via indexing, query rewriting, statistics, and configuration.
- Query profiling
Show answerHide answer
Measuring a query's resource use and timing to find bottlenecks.
- Locking
Show answerHide answer
Preventing conflicting concurrent access to data to preserve isolation.
- Deadlock
Show answerHide answer
Two transactions each hold a lock the other needs; the DBMS kills one as the victim.
- Lock escalation
Show answerHide answer
The DBMS converting many fine-grained locks into a coarser one to save resources.
- Concurrency
Show answerHide answer
Multiple transactions executing at the same time without corrupting data.
- Isolation level
Show answerHide answer
Sets how visible one transaction's changes are to others (read committed, serializable, etc.).
- Dirty read
Show answerHide answer
Reading uncommitted changes that may later be rolled back.
- Phantom read
Show answerHide answer
Rows appearing/disappearing between reads in a transaction due to other inserts/deletes.
- Database job / scheduler
Show answerHide answer
Automated, scheduled task: backups, index maintenance, statistics updates, cleanup.
- Patching
Show answerHide answer
Applying vendor updates to the DBMS to fix bugs and close security holes.
- Maintenance plan
Show answerHide answer
A scheduled set of upkeep tasks: backups, integrity checks, index/statistics maintenance.
- Integrity check (DBCC)
Show answerHide answer
A consistency check (e.g., DBCC CHECKDB) that detects corruption in a database.
- Capacity planning
Show answerHide answer
Forecasting storage, memory, and CPU needs to keep performance acceptable as data grows.
- Monitoring
Show answerHide answer
Continuously tracking health metrics (CPU, memory, I/O, waits, blocking, errors).
- Baseline (performance)
Show answerHide answer
A record of normal performance used to spot abnormal drift.
- Alerting
Show answerHide answer
Automated notifications when a metric crosses a threshold (e.g., low disk, high latency).
- Log file (transaction log)
Show answerHide answer
Records all changes so transactions can be committed, rolled back, and recovered.
- Log truncation
Show answerHide answer
Reclaiming space in the transaction log after backups, preventing it from filling.
- Partitioning
Show answerHide answer
Splitting a large table across segments to improve manageability and performance.
- Sharding
Show answerHide answer
Horizontally splitting data across multiple servers to scale out.
- Archiving
Show answerHide answer
Moving old, rarely accessed data to cheaper storage to keep active tables lean.
- Vacuum / cleanup
Show answerHide answer
Reclaiming space from dead rows and updating statistics (e.g., PostgreSQL VACUUM).
- Connection pooling
Show answerHide answer
Reusing a set of database connections to reduce overhead and improve throughput.
- Resource governor
Show answerHide answer
A feature that caps CPU/memory per workload to prevent one query starving others.
- Wait statistics
Show answerHide answer
Metrics showing what the engine is waiting on (I/O, locks, CPU) to find bottlenecks.
- Blocking
Show answerHide answer
One transaction holding a lock that stalls another (not yet a deadlock).
- Query hint
Show answerHide answer
An instruction that overrides the optimizer's default choice for a query.
- Parameter sniffing
Show answerHide answer
The optimizer caching a plan based on the first parameter, hurting other values.
- Plan cache
Show answerHide answer
Stored execution plans reused to avoid recompiling frequent queries.
- Recompilation
Show answerHide answer
Generating a fresh execution plan when data or statistics change significantly.
- Database integrity
Show answerHide answer
The overall accuracy and consistency of data, protected by constraints and checks.
- Orphaned user
Show answerHide answer
A database user whose matching server login is missing — a common post-restore fix.
- Tempdb / temp space
Show answerHide answer
Workspace the engine uses for sorts, joins, and temporary objects.
- Autogrowth
Show answerHide answer
A setting that lets a data/log file expand automatically when it fills.
- Compression (DB)
Show answerHide answer
Reducing storage and I/O by compressing data or backups.
- Health check
Show answerHide answer
A routine review of performance, errors, security, and backups.
- Refresh statistics
Show answerHide answer
Updating data-distribution stats so the optimizer makes good choices.
- Maintenance window
Show answerHide answer
A scheduled period for disruptive upkeep (patching, rebuilds) with low user impact.
Data and Database Security (52)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core security goals.
- Confidentiality
Show answerHide answer
Keeping data accessible only to authorized parties (encryption, access control).
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered except by authorized changes.
- Availability
Show answerHide answer
Ensuring data and the database are accessible when needed.
- Authentication
Show answerHide answer
Verifying who a user or service is (passwords, keys, MFA, certificates).
- Authorization
Show answerHide answer
Determining what an authenticated user is allowed to do.
- RBAC
Show answerHide answer
Role-Based Access Control — assign permissions to roles, then users to roles.
- Least privilege
Show answerHide answer
Granting only the minimum access a role needs to do its job.
- Principle of separation of duties
Show answerHide answer
Splitting critical tasks among people so no one has unchecked control.
- GRANT
Show answerHide answer
SQL (DCL) command that gives a user or role a permission.
- REVOKE
Show answerHide answer
SQL (DCL) command that removes a previously granted permission.
- SQL injection
Show answerHide answer
Inserting malicious SQL via unsanitized input to read or alter data.
- Parameterized query
Show answerHide answer
A prepared statement that separates SQL code from input — the main SQL-injection defense.
- Input validation
Show answerHide answer
Checking and sanitizing user input to block malicious or malformed data.
- Encryption at rest
Show answerHide answer
Encrypting stored data on disk so files/backups are unreadable if stolen.
- Encryption in transit
Show answerHide answer
Encrypting data moving over the network (TLS) so it can't be intercepted.
- TDE
Show answerHide answer
Transparent Data Encryption — encrypts database files at rest automatically.
- TLS
Show answerHide answer
Transport Layer Security — the protocol that encrypts data in transit between client and server.
- AES
Show answerHide answer
Advanced Encryption Standard — a strong symmetric cipher widely used for data encryption.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest; used to store passwords (with salt).
- Salt
Show answerHide answer
Random data added to a password before hashing to defeat precomputed (rainbow) attacks.
- Key management
Show answerHide answer
Securely generating, storing, rotating, and revoking encryption keys.
- Data masking
Show answerHide answer
Hiding sensitive values (e.g., showing only last 4 digits) for non-privileged users.
- Tokenization
Show answerHide answer
Replacing sensitive data with a non-sensitive token mapped in a secure vault.
- Auditing
Show answerHide answer
Recording who accessed or changed what and when, for accountability and compliance.
- Audit log
Show answerHide answer
An immutable record of security-relevant database events.
- Data classification
Show answerHide answer
Labeling data by sensitivity (public, internal, confidential, restricted) to drive controls.
- PII
Show answerHide answer
Personally Identifiable Information — data that can identify a person; requires protection.
- GDPR
Show answerHide answer
EU regulation governing personal-data privacy, consent, and breach notification.
- HIPAA
Show answerHide answer
U.S. law protecting the privacy and security of health information (PHI).
- PCI DSS
Show answerHide answer
Security standard for organizations that handle payment-card data.
- Privilege escalation
Show answerHide answer
An attacker gaining higher permissions than they were granted.
- Defense in depth
Show answerHide answer
Layering multiple security controls so no single failure exposes the data.
- Database firewall
Show answerHide answer
A control that monitors and filters SQL traffic to block malicious queries.
- Backup encryption
Show answerHide answer
Encrypting backup files so stolen backups don't expose data.
- Account lockout
Show answerHide answer
Disabling an account after repeated failed logins to slow brute-force attacks.
- Service account
Show answerHide answer
A non-human account an application uses; should run with least privilege.
- MFA
Show answerHide answer
Multi-Factor Authentication — requiring two or more proofs of identity.
- Certificate authentication
Show answerHide answer
Using digital certificates to verify identity instead of passwords.
- Row-level security
Show answerHide answer
Restricting which rows a user can see based on their identity or role.
- Column-level security
Show answerHide answer
Restricting access to specific sensitive columns within a table.
- Dynamic data masking
Show answerHide answer
Masking column values at query time for unauthorized users without changing stored data.
- Vulnerability assessment
Show answerHide answer
Scanning a database for misconfigurations and known weaknesses.
- Penetration test
Show answerHide answer
An authorized simulated attack to find exploitable security gaps.
- Patch (security)
Show answerHide answer
A fix that closes a known vulnerability in the DBMS.
- Brute-force attack
Show answerHide answer
Trying many passwords/keys until one works; mitigated by lockout and strong policies.
- Privilege creep
Show answerHide answer
Users accumulating permissions over time beyond what they currently need.
- Data breach
Show answerHide answer
Unauthorized access to or disclosure of protected data.
- Incident response
Show answerHide answer
The plan to detect, contain, eradicate, and recover from a security incident.
- Compliance audit
Show answerHide answer
A formal review confirming controls meet a regulation or standard.
- Data sovereignty
Show answerHide answer
The principle that data is subject to the laws of the country where it is stored.
- Secure baseline
Show answerHide answer
A hardened default configuration applied to every database.
Business Continuity (48)
- RPO
Show answerHide answer
Recovery Point Objective — the maximum tolerable data loss; drives backup frequency.
- RTO
Show answerHide answer
Recovery Time Objective — the maximum tolerable downtime; drives recovery design.
- Full backup
Show answerHide answer
A complete copy of all data; fastest restore, most storage and time.
- Differential backup
Show answerHide answer
Copies all changes since the last FULL backup; restore = full + latest differential.
- Incremental backup
Show answerHide answer
Copies changes since the last backup of ANY type; smallest, but slowest restore.
- 3-2-1 rule
Show answerHide answer
Keep 3 copies of data, on 2 media types, with 1 copy off-site.
- Backup verification
Show answerHide answer
Testing that backups actually restore — an untested backup is unproven.
- Cold backup
Show answerHide answer
A backup taken while the database is shut down (offline).
- Hot backup
Show answerHide answer
A backup taken while the database is running and online.
- Point-in-time recovery
Show answerHide answer
Restoring a database to a specific moment using backups plus transaction logs.
- Snapshot
Show answerHide answer
A read-only, point-in-time image of data used for fast recovery or cloning.
- RAID 0
Show answerHide answer
Striping for speed; no redundancy — one disk failure loses all data.
- RAID 1
Show answerHide answer
Mirroring — an identical copy on a second disk; survives one disk failure.
- RAID 5
Show answerHide answer
Striping with distributed parity; survives one disk failure; needs 3+ disks.
- RAID 6
Show answerHide answer
Double parity; survives two simultaneous disk failures; needs 4+ disks.
- RAID 10
Show answerHide answer
Mirrored pairs that are striped; high performance and redundancy.
- High availability (HA)
Show answerHide answer
Designing systems to minimize downtime through redundancy and failover.
- Failover
Show answerHide answer
Automatically switching to a standby system when the primary fails.
- Failover cluster
Show answerHide answer
Multiple nodes sharing storage so a standby can take over the database service.
- Replication
Show answerHide answer
Keeping synchronized copies of a database on multiple servers.
- Synchronous replication
Show answerHide answer
Commits on the primary and replica together — zero data loss, higher latency.
- Asynchronous replication
Show answerHide answer
Replica lags slightly behind — lower latency, small risk of data loss.
- Log shipping
Show answerHide answer
Periodically copying and restoring transaction logs to a standby server.
- Mirroring (DB)
Show answerHide answer
Maintaining a hot standby copy of a database for failover.
- Disaster recovery (DR)
Show answerHide answer
The plan and process to restore service after a major outage or disaster.
- DR site
Show answerHide answer
A secondary location (hot, warm, or cold) used to resume operations after a disaster.
- Hot site
Show answerHide answer
A fully equipped, running DR site that can take over almost immediately.
- Warm site
Show answerHide answer
A partially ready DR site needing some setup/data load before takeover.
- Cold site
Show answerHide answer
A facility with infrastructure but no live systems/data — slowest to bring up.
- Business continuity plan (BCP)
Show answerHide answer
An organization-wide plan to keep critical functions running during disruption.
- MTTR
Show answerHide answer
Mean Time To Repair — average time to fix a failed component.
- MTBF
Show answerHide answer
Mean Time Between Failures — average operating time between failures (reliability).
- Geo-redundancy
Show answerHide answer
Storing copies in geographically separate regions to survive a regional outage.
- Retention policy
Show answerHide answer
Rules for how long backups/data are kept before deletion or archive.
- Standby database
Show answerHide answer
A secondary copy kept ready to take over (warm/hot) if the primary fails.
- Active-active
Show answerHide answer
Both nodes serve traffic simultaneously, sharing load and providing redundancy.
- Active-passive
Show answerHide answer
One node serves traffic while a standby waits to take over on failure.
- Quorum
Show answerHide answer
The minimum number of cluster nodes that must agree for the cluster to stay online.
- Split-brain
Show answerHide answer
A cluster fault where two nodes both think they're primary — prevented by quorum/witness.
- Witness / arbiter
Show answerHide answer
An extra vote that breaks ties and prevents split-brain in a cluster.
- Backup window
Show answerHide answer
The time period available to run backups without harming performance.
- Backup retention
Show answerHide answer
How long backup copies are kept before deletion (driven by policy/compliance).
- Offsite backup
Show answerHide answer
A backup stored in a separate location to survive a site-level disaster.
- Tabletop exercise
Show answerHide answer
A walkthrough drill that tests a DR/BCP plan without real failover.
- Recovery testing
Show answerHide answer
Periodically restoring backups to prove they work and meet the RTO.
- Bare-metal recovery
Show answerHide answer
Restoring a full system, including OS, from backup onto new hardware.
- Continuous data protection
Show answerHide answer
Capturing every change so you can restore to nearly any point in time.
- SLA
Show answerHide answer
Service Level Agreement — the committed uptime/recovery targets for a service.
References
- 1.CompTIA. “DataSys+ (DS0-001) Certification Exam Objectives.” comptia.org. ↑
- 2.International Organization for Standardization. “ISO/IEC 9075 — Database language SQL.” iso.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-53 — Security and Privacy Controls.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
