Question 1
IntermediateIntroduction to Auditing · Create, Modify and Maintain Database Auditing
A financial services company is implementing a unified audit policy named FIN_AUDIT_POLICY to monitor all SELECT, INSERT, and UPDATE operations on the CUSTOMERS table. After enabling the policy, the security officer notices that actions performed by the SYS user are not being captured. What must be done to ensure SYS user actions are also audited by this policy?
Answer and explanation
Correct answer: C
By default, the SYS user is excluded from unified audit policies to prevent excessive audit record generation from routine administrative tasks. To include SYS actions, the AUDIT_SYS_OPERATIONS initialization parameter must be set to TRUE. The other options are syntactically incorrect or do not achieve the desired outcome; policies are not enabled with a BY SYS clause in the AUDIT statement itself.
