Be able to choose the right MDM, classification, and stewardship approach for a multi-org scenario, and assign each responsibility to the correct role. The single most important thing: governance is policy plus ownership plus enforcement, not just a Salesforce feature.
Start practicing
Data Governance — choose a session length
Free · No account required
Domain overview
Data Governance on the Salesforce Data Architecture and Management Designer exam covers MDM golden records, data stewardship roles, classification and protection of sensitive data, and Data Governance Council outcomes. Questions are scenario-based: you pick the framework component, steward responsibility, or council goal that best fits a multi-org, auditable enterprise requirement.
Exam objectives
Selecting MDM patterns that keep a single golden record consistent across Salesforce Orgs and external systems
Data Steward duties: data quality monitoring, metadata and definition ownership, issue remediation, and policy enforcement
Using Data Classification, Shield Platform Encryption, Event Monitoring, and Field Audit Trail for sensitive data categorization, protection, and audit
Data Governance Council goals: policy ownership, cross-functional decision rights, standards, and stewardship accountability
Treating Data Governance as a one-time project or tool purchase instead of ongoing policy, ownership, and stewardship across Orgs.
Confusing Data Steward responsibilities with those of the Data Governance Council or executive sponsor, such as budget and enterprise strategy.
Assuming Shield Platform Encryption or classic audit fields alone satisfy classification, retention, and auditability requirements without governance policy.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A global organization requires that sensitive customer data be categorized, protected, and auditable across Salesforce Orgs. Which data governance framework component is most effective for ensuring consistent data classification policies?
2A firm is implementing a data stewardship program. Which TWO activities are primary responsibilities of a Data Steward? (Choose Two)
3Refer to the exhibit. An organization uses the provided JSON policy to manage PII fields. As a Data Architect, what is the primary governance risk if this policy is not integrated with Salesforce's internal security controls?
4Which document is the most critical for Data Governance to ensure that Salesforce Orgs remain compliant with regional data residency requirements?
5An organization is establishing a Data Governance Council. Which THREE outcomes are primary goals of this council? (Choose Three)
6Which strategy best supports Data Governance when scaling a Salesforce implementation across multiple business units with varying data requirements?
7A Data Architect is tasked with ensuring Data Lifecycle Management is governed. Which lifecycle stage should include a requirement for automated data archiving?
8What is the primary role of a Data Dictionary in a Data Governance program?
9An architect is designing a governance framework for Master Data Management (MDM). Which approach is best for ensuring 'Golden Record' consistency in Salesforce?
10Which governance component ensures that Salesforce Orgs are prepared for major feature updates and potential breaking changes?
11Refer to the exhibit. As a Data Architect, what is the governance concern if this 'VAL-099' rule remains inactive in production?
12Which document is essential to provide to a regulator to prove that the Data Governance program is active and effective?
13Universal Containers needs to establish a formalized Data Governance framework to manage customer data across multiple Salesforce orgs and external systems. Which foundational element must the Data Governance board define first to ensure enterprise-wide alignment and accountability?
14A financial services firm is implementing Salesforce and must ensure PII data is managed according to strict regional privacy regulations. Which data governance framework component is most essential for tracking data lifecycle stages from collection to deletion?
15A large enterprise is struggling with inconsistent data quality across multiple business units. They want to establish a Data Governance Council. Who should lead this council to ensure the initiative receives adequate executive sponsorship and alignment with corporate strategy?
16A company is defining its Data Stewardship model. Which THREE responsibilities are typically assigned to a Data Steward within a Salesforce-centric data governance framework? (Choose three.)
17A global Salesforce org maintains an Account record that is simultaneously updated by an inbound ERP integration, a nightly Data Loader batch, and a sales rep via the Lightning UI. During a data quality audit, the governance board finds that conflicting values for the 'Annual Revenue' field have overwritten each other, and no one can determine which source was authoritative at any point in time. The board wants to ensure that future conflicts are detected, attributed to a source system, and resolved according to a documented priority order before the record is committed. Which governance mechanism should the Data Architect recommend to satisfy this requirement?
18A multinational manufacturer runs a single Salesforce org for sales and service. Its governance team wants to enforce that all new custom objects created in production carry a business owner, a retention classification, and a data sensitivity label. Administrators frequently create objects ad hoc, and the team wants an automated check rather than a manual review. Which approach should the data architect recommend?
19A financial services company must retain Salesforce records for seven years to satisfy a regulator. Records older than two years are rarely accessed but must remain retrievable within 48 hours if requested. The org's data volume is growing 40 percent per year, and the architect wants to minimize storage cost while preserving the ability to restore records with their original Salesforce IDs and relationships. Which approach best meets these requirements?
20Universal Containers is building a Data Governance program for its Salesforce org. The governance lead wants a single authoritative reference that defines every custom object and field, its business definition, data owner, allowed values, and system of record. Which artifact should the architect recommend as the foundation?
21An enterprise Salesforce org has multiple business units that each maintain their own picklist values for the Industry field on Account. This has caused inconsistent reporting and integration failures. The Data Governance Council mandates a single, standardized Industry picklist across all business units. Which approach best enforces this standardization while allowing controlled local extensions?
22Northern Trail Outfitters is preparing for a GDPR-driven data subject deletion request affecting a Contact and its related Cases, Email Messages, and custom child records. The architect must ensure the deletion is complete and evidenced. Which approach best satisfies the governance requirement?
23A Salesforce org has a data governance policy that requires all new custom objects to have a description and a data owner assigned before deployment to production. The architect needs to enforce this policy automatically during the development lifecycle. Which approach should the architect take?
24A Salesforce org has a data governance policy that requires all new custom objects and fields to be reviewed and approved by a data governance council before creation. A developer needs to add a new field to the Account object to support a critical business process. What should the developer do first?
25A multinational financial services company uses Salesforce to manage customer interactions. Its data governance team must ensure that all data elements containing Personally Identifiable Information (PII) are consistently classified, protected, and auditable across Production and Full Sandbox environments. The team is considering using Salesforce Data Mask to anonymize PII in Full Sandboxes. However, they are concerned that masking might alter the original data in Production. What is the most accurate statement regarding Data Mask and its role in this governance strategy?
26A multinational Salesforce org must ensure that records created in the EU region are stored and processed only within EU-approved infrastructure, while global reporting aggregates anonymized metrics. Which governance control should the architect prioritize to satisfy data residency?
27Universal Containers maintains a single Salesforce org used by sales teams across North America, EMEA, and APAC. Each region has its own legal requirements for how long personal data may be retained. The VP of Sales wants one consistent retention policy applied everywhere to simplify administration. As the data architect, what should you recommend?
28A Salesforce org is implementing a data governance program to manage data quality for a large volume of customer records. The architect must recommend tools and features to monitor and improve data quality on an ongoing basis. Which two Salesforce features should be used to proactively identify and address data quality issues? (Choose two.)
29A retail company wants to ensure that customer email addresses are consistently formatted and that invalid values are rejected at the point of entry across web, mobile, and integration channels. The data governance lead asks the architect which Salesforce feature provides a single, reusable definition of the validation that all channels can share. Which feature should the architect recommend?
30A healthcare organization uses Salesforce to manage patient cases and must comply with HIPAA. The data governance team needs to ensure that audit trails for access to Protected Health Information (PHI) are comprehensive and tamper-evident. They are evaluating Salesforce Shield Event Monitoring and Field Audit Trail. Which combination of features should the team implement to meet the requirement for tracking who accessed PHI fields and when, while also retaining the audit data for 10 years?
31A multinational company uses Salesforce across multiple regions. Each region has its own data retention requirements: the EU requires customer data to be deleted after 7 years, while the US requires retention for 10 years. The company wants to implement a data lifecycle governance policy that automatically enforces these retention periods. Which solution should the data architect recommend?
32The governance board at a financial services firm wants to know when critical fields on the Opportunity object were changed, who changed them, and what the previous value was, without writing custom code. Which native capability should the architect enable?
33Northern Trail Outfitters has a Salesforce org where the Account object contains 40 custom fields, many of which were created by different teams over five years. No one is certain which fields are actively used, which are populated by integrations, and which are safe to remove. The CIO asks the data architect to establish ongoing visibility into field usage and data provenance. Which approach best addresses this governance gap?
34A global insurer is preparing for a data privacy audit. The architect must demonstrate that the Salesforce org can identify where personal data lives and prove who accessed it. Which two capabilities should the architect include in the governance solution? (Choose two.)
35A retail company is implementing a data governance program and needs to define ownership and accountability for data quality. The company has multiple business units, each using Salesforce differently. The governance team wants to ensure that each data domain (e.g., Customer, Product, Order) has a clear owner responsible for data quality, definitions, and issue resolution. Which role should be assigned to fulfill this responsibility?
36A global Salesforce org has implemented a data governance framework. The governance team needs to ensure that data is retained according to legal and regulatory requirements, and that it is securely deleted when no longer needed. They are evaluating Salesforce's native capabilities for data lifecycle management. Which statement accurately describes a limitation or behavior of Salesforce's native data retention and deletion features that the team must consider?
37A healthcare organization is building a data governance program for its Salesforce org. The compliance officer wants a documented record of who owns each data domain, what the approved data definitions are, and how changes to those definitions are approved. Which artifact should the architect establish as the authoritative source for this information?
Be able to choose the right MDM, classification, and stewardship approach for a multi-org scenario, and assign each responsibility to the correct role. The single most important thing: governance is policy plus ownership plus enforcement, not just a Salesforce feature.
The Courseiva SF-Data-Arch question bank contains 37 questions in the Data Governance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Governance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included