Bird
Raised Fist0
SQLquery~30 mins

Views for security and abstraction in SQL - Mini Project: Build & Apply

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Views for Security and Abstraction
📖 Scenario: You work for a company that stores employee information in a database. Some details, like salaries, should be kept private. You want to create a simple way for managers to see employee names and departments without exposing sensitive data.
🎯 Goal: Create a database view that shows only employee names and their departments. This view will help managers access necessary information securely without seeing confidential details like salaries.
📋 What You'll Learn
Create a table called employees with columns id, name, department, and salary.
Insert exactly three employees with specified values.
Create a view called employee_overview that shows only name and department from employees.
Use the view to select all employee names and departments.
💡 Why This Matters
🌍 Real World
Companies often need to protect sensitive employee data while allowing managers to see relevant information. Views help by showing only what is necessary.
💼 Career
Database administrators and developers use views to control data access and simplify complex data structures for different users.
Progress0 / 4 steps
1
Create the employees table and insert data
Create a table called employees with columns id (integer), name (text), department (text), and salary (integer). Then insert these three employees exactly: (1, 'Alice', 'HR', 50000), (2, 'Bob', 'IT', 60000), and (3, 'Charlie', 'Finance', 55000).
SQL
Hint

Use CREATE TABLE to define the table and INSERT INTO to add the rows.

2
Define the view employee_overview
Create a view called employee_overview that selects only the name and department columns from the employees table.
SQL
Hint

Use CREATE VIEW view_name AS SELECT ... to define the view.

3
Query the employee_overview view
Write a SQL query to select all columns from the employee_overview view.
SQL
Hint

Use SELECT * FROM employee_overview; to get all rows and columns from the view.

4
Secure the view by restricting direct access to employees
Add a SQL statement to revoke direct SELECT access on the employees table from public users, so only the view employee_overview can be used to see employee names and departments.
SQL
Hint

Use REVOKE SELECT ON employees FROM PUBLIC; to restrict direct access.

Practice

(1/5)
1. What is the main purpose of using a VIEW in SQL?
easy
A. To permanently store data in the database
B. To provide a simplified and secure way to access specific data
C. To create a backup of the database
D. To speed up the database server hardware

Solution

  1. Step 1: Understand what a VIEW is

    A VIEW is a virtual table created by a SELECT query that shows data without storing it separately.
  2. Step 2: Identify the purpose of a VIEW

    It helps users see only the data they need, hiding sensitive details and simplifying complex queries.
  3. Final Answer:

    To provide a simplified and secure way to access specific data -> Option B
  4. Quick Check:

    VIEW = Simplify + Secure access [OK]
Hint: Views show selected data safely without storing it separately [OK]
Common Mistakes:
  • Thinking views store data permanently
  • Confusing views with backups
  • Believing views improve hardware speed
2. Which of the following is the correct syntax to create a view named EmployeeView showing only EmployeeID and Name from Employees table?
easy
A. CREATE VIEW EmployeeView AS SELECT EmployeeID, Name FROM Employees;
B. MAKE VIEW EmployeeView SELECT EmployeeID, Name FROM Employees;
C. CREATE TABLE EmployeeView AS SELECT EmployeeID, Name FROM Employees;
D. VIEW CREATE EmployeeView SELECT EmployeeID, Name FROM Employees;

Solution

  1. Step 1: Recall the correct SQL syntax for creating a view

    The syntax is: CREATE VIEW view_name AS SELECT columns FROM table;
  2. Step 2: Match the syntax with options

    CREATE VIEW EmployeeView AS SELECT EmployeeID, Name FROM Employees; matches the correct syntax exactly.
  3. Final Answer:

    CREATE VIEW EmployeeView AS SELECT EmployeeID, Name FROM Employees; -> Option A
  4. Quick Check:

    CREATE VIEW ... AS SELECT ... [OK]
Hint: Use CREATE VIEW ... AS SELECT ... to define views [OK]
Common Mistakes:
  • Using MAKE VIEW instead of CREATE VIEW
  • Confusing CREATE VIEW with CREATE TABLE
  • Incorrect keyword order
3. Given the table Employees with columns EmployeeID, Name, Salary, and a view EmployeeView defined as:
CREATE VIEW EmployeeView AS SELECT EmployeeID, Name FROM Employees;

What will the query SELECT * FROM EmployeeView; return?
medium
A. Only Salary column
B. All columns: EmployeeID, Name, Salary
C. Only EmployeeID and Name columns
D. Syntax error because Salary is missing

Solution

  1. Step 1: Understand the view definition

    The view selects only EmployeeID and Name columns from Employees.
  2. Step 2: Determine what SELECT * from the view returns

    It returns only the columns defined in the view, which are EmployeeID and Name.
  3. Final Answer:

    Only EmployeeID and Name columns -> Option C
  4. Quick Check:

    View columns = Selected columns only [OK]
Hint: View shows only columns defined in its SELECT query [OK]
Common Mistakes:
  • Expecting all original table columns
  • Thinking missing columns cause syntax errors
  • Confusing view columns with table columns
4. Consider this incorrect SQL statement to create a view:
CREATE VIEW SalesView SELECT OrderID, Amount FROM Sales;

What is the error and how to fix it?
medium
A. Incorrect view name; fix by renaming view
B. Missing FROM keyword; fix by adding FROM before Sales
C. SELECT statement is not allowed in views
D. Missing AS keyword; fix by adding AS after view name

Solution

  1. Step 1: Identify the syntax error in CREATE VIEW

    The correct syntax requires AS keyword after the view name.
  2. Step 2: Correct the statement

    Add AS after SalesView: CREATE VIEW SalesView AS SELECT OrderID, Amount FROM Sales;
  3. Final Answer:

    Missing AS keyword; fix by adding AS after view name -> Option D
  4. Quick Check:

    CREATE VIEW ... AS SELECT ... [OK]
Hint: Always use AS after view name in CREATE VIEW [OK]
Common Mistakes:
  • Omitting AS keyword
  • Misplacing FROM keyword
  • Thinking SELECT is disallowed in views
5. You want to create a view PublicEmployeeData that hides the Salary column from the Employees table but allows users to see EmployeeID, Name, and Department. Which SQL statement correctly creates this view and ensures security by restricting access to sensitive data?
hard
A. CREATE VIEW PublicEmployeeData AS SELECT EmployeeID, Name, Department FROM Employees;
B. CREATE VIEW PublicEmployeeData AS SELECT * FROM Employees WHERE Salary IS NULL;
C. CREATE VIEW PublicEmployeeData AS SELECT EmployeeID, Name, Department, Salary FROM Employees;
D. CREATE VIEW PublicEmployeeData AS SELECT EmployeeID, Name FROM Employees;

Solution

  1. Step 1: Identify columns to include and exclude

    We want EmployeeID, Name, Department but NOT Salary to protect sensitive data.
  2. Step 2: Choose the correct SELECT statement for the view

    CREATE VIEW PublicEmployeeData AS SELECT EmployeeID, Name, Department FROM Employees; selects only the allowed columns, hiding Salary effectively.
  3. Final Answer:

    CREATE VIEW PublicEmployeeData AS SELECT EmployeeID, Name, Department FROM Employees; -> Option A
  4. Quick Check:

    View excludes Salary to secure sensitive data [OK]
Hint: Select only non-sensitive columns in view to protect data [OK]
Common Mistakes:
  • Including Salary column accidentally
  • Using WHERE Salary IS NULL which filters rows, not columns
  • Selecting too few columns missing Department