skip to content

A compromised read-only auditor account could query a regulated customer table — what must you establish before grading that as data exposure?

level: juniorimportance: must knowfreq 74%

answer

  1. two claims, not one
  2. grants describe reach
  3. who could read versus who did
  4. query rows name tables and columns
  5. silence needs logging that was on

basics

~20 s

Entitlement is not access. The account's grants tell you what was reachable; only the warehouse's query-audit records tell you which tables and columns were actually read. Grade the reach now, call it exposure only where query evidence supports it.

solid answer

~50 s

Two separate claims are in play, and an interviewer wants to hear you keep them apart. The first is **reach**: the grants attached to that identity, plus any role it could assume, define the set of data that was exposed to whoever held the credential. The second is **evidenced access**: the warehouse's per-query audit records name the statements run, the objects and columns they touched, and the rows returned. Grade the reach immediately — that is what you actually know at hour two, and it is what drives staffing and evidence preservation. Do not escalate the wording to `customer data was read` until the query records support it. Be just as careful in the other direction: an empty query log only means something if object-level query auditing was enabled for that warehouse across the whole window and the records are still inside retention. And a successful authentication proves a credential was accepted, not that its named owner was present.

code

json · 13 lines
json
{
  "query_id": "01b2f8c4-...",
  "start_time": "2026-03-11T02:41:07Z",
  "user_name": "svc_audit_ro",
  "role_name": "AUDITOR_READONLY",
  "query_type": "SELECT",
  "objects_accessed": [
    { "table": "FIN.CUSTOMER_ACCOUNT",
      "columns": ["ACCOUNT_ID", "LEGAL_NAME", "TAX_ID"] }
  ],
  "rows_produced": 412873,
  "client_ip": "203.0.113.44"
}

go deeper

for a junior

Be ready to say plainly that a permission grant and a query-audit record answer different questions, and to name which of the two supports the sentence 'customer data was read'.

for a middle

Expect to explain where the evidence comes from — per-query audit records naming objects, columns and rows returned — and what conditions must hold before their silence means anything at all.

for a senior

Show that you grade reach at hour two rather than waiting for proof, and that you publish reach and evidenced access as separate numbers so nobody downstream collapses them into one.

for a principal

Own the consequence: the grade you publish starts notification assessments and spend, so the organisation needs a standing convention for how a reach-based grade is worded, who may restate it, and when it is revisited.

## The two claims a severity grade rests on Grading a declared intrusion by what the intruder *reached* means holding two different claims at once, with two different kinds of support behind them. **Reach** is what the compromised identity was entitled to obtain. It comes from configuration, not from behaviour: the grants attached to the account, the roles it is permitted to assume, the groups it belongs to, and the classification labels on the datasets those grants cover. Reach is knowable within minutes of identifying the account, because it is a property of the environment rather than of the incident. It is also the honest thing to grade on early — you can say with high confidence *this credential was in a position to read the customer account table* long before you can say anything about what it did. **Evidenced access** is what records prove was obtained. In a data warehouse that evidence is the per-query audit trail: one row per statement, naming the identity and role that ran it, the objects accessed down to the column list, the row count produced, and the client address. That is the only artefact that converts *could have read* into *read*. Collapsing the two is the most common wrong answer in this area, and it fails in both directions. Reporting reach as exposure over-claims, and the over-claim is expensive: an exposure statement drives notification assessments, customer conversations and legal cost that you may not be able to withdraw. Reporting only evidenced access under-claims, because at hour two you have almost none of it, and a grade built on an empty evidence set will be far too low for the staffing and evidence-preservation decisions it is about to drive. ## Why silence in the log is not an answer Candidates reach reflexively for *there are no queries from that account, so nothing was read*. That inference is only available if three things hold: the auditing that would have written the row was actually enabled for that warehouse, it was enabled for the entire window in question, and the records for that window have not aged out of retention. If any of those fails, the absence of a record is uninformative — it tells you about your collection, not about the intruder. Treat any window without coverage as reachable-until-disproven and say so explicitly in the grade's basis, rather than letting a coverage gap silently read as a clean window. The same discipline applies to the identity itself. A successful authentication event proves a credential was accepted by the identity provider. It does not prove a person was at a keyboard, and it does not identify which person. Attribution needs other evidence: the source address and device, whether the session arrived over an expected network path, whether the named owner was working at that hour, and whether the same credential appears in concurrent use somewhere else. ## What you actually write down at hour two A defensible early grade is stated as two components with two confidences: - *Reach*: the identity held read across the finance and customer schemas, including two tables carrying regulated identifiers. Confidence high — derived from the grant configuration as it stood at the time of compromise. - *Evidenced access*: three SELECT statements confirmed against one non-regulated table. Confidence partial — the full query set for the window is still being retrieved. And then the trigger that will move it: *the grade is revisited when the complete query set for the window is in hand, and immediately if any statement touching a regulated table appears.* Naming the trigger at declaration time is what stops the low, evidence-based half from being read as a final verdict by everyone downstream. ## Reach is graded on what the grants covered, not on the worst thing in the estate The opposite failure is grading the schema on its most sensitive table when the identity never had a grant reaching it. Reach is bounded by the grants; the exercise is to enumerate the grants and join them to the classification of the datasets they cover, not to reason from the scariest thing that lives in the same database. Where the grant enumeration itself is uncertain — inherited group membership, a role the account could assume — that uncertainty belongs in the grade's basis as a named open question, because it is exactly the thing that will move the grade later. ## The direction of every claim Hold these apart, because interviewers probe them directly. A grant proves *reachability*. A query-audit row proves *a read*. Egress evidence — a byte count leaving toward an unexpected destination — proves *data moved*, and even then flow records carry the five-tuple, counts and timestamps and no payload at all, so they show that bytes moved and never what they were. Each is a different claim with a different piece of evidence behind it, and a grade that mixes them up is a grade that cannot be defended when someone asks how you know.

  • The warehouse shows no query from that account in the window — can you close the exposure question?
    Only if object-level query auditing was enabled for that warehouse across the whole window and the records are still inside retention. Otherwise the absence is uninformative: no record was written, and that says something about your collection rather than about the intruder. State what the log can and cannot support, and treat any uncovered window as reachable-until-disproven.
  • How do you word the severity at hour two while query records are still being pulled?
    As two components with two confidences: reach, graded from the identity's grants and the classification of the datasets they covered, held at high confidence; and evidenced access, graded from the records in hand, marked explicitly partial. Then name the regrade trigger, so nobody downstream reads the evidence half as a final verdict.
  • Does a successful sign-in by that auditor account tell you a person signed in?
    No. A successful authentication event proves a credential was accepted by the identity provider. Attribution to a human needs separate evidence — the source address and device, whether the session came over an expected path, whether the named owner was working, and whether the same credential is in concurrent use elsewhere.

A hotel master key proves which doors a holder could open. Only the door-reader log shows which ones they walked through — and only if the readers were switched on.

saying these in an interview costs you the question

  • Treats 'had access to' and 'accessed' as the same claim
  • Says an empty audit log proves nothing was read
  • Grades the whole schema on its most sensitive table without checking the grants
  • Assumes a successful sign-in identifies the human behind it
  • Refuses to assign any grade until the evidence is complete

context