Courseiva

DS0-001 · domain

Data Governance And Security

Practise CompTIA DataSys+ (DS0-001) (DS0-001) Data Governance And Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

49 questions13 easy21 medium15 hard

Focused practice

Practice Data Governance And Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Data Governance And Security

Data Governance And Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Data Governance And Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Data Governance And Security questions (49)

Click any question to see the full explanation, or start a practice session above.

1

Which access control model should be implemented to ensure that a user can only access files based on their specific job role?

Easy
2

A developer wants to use a subset of production data for testing. Which method ensures the test data retains its structure while protecting privacy?

Medium
3

Your organization uses Azure Active Directory for access management. You need to ensure that database administrators can only access a specific production Azure SQL instance during a scheduled 4-hour maintenance window. Which control is most appropriate?

Hard
4

A company subject to GDPR needs to ensure that user data is deleted upon request across all distributed nodes in a NoSQL cluster. Which process is most critical to demonstrate compliance?

Hard
5

Which TWO of the following are recognized components of a mature Data Governance framework? (Select TWO)

Medium
6

An organization is migrating sensitive financial records to a cloud environment. Which security control ensures that only authorized applications can decrypt the data?

Hard
7

A company is conducting a data governance audit. Which TWO of the following items should be verified to ensure proper data security?

Easy
8

Which regulatory act specifically governs the protection of healthcare-related data?

Easy
9

You are implementing a data governance framework. Which role is primarily responsible for ensuring that the data quality, security, and lifecycle policies are defined and adhered to for a specific business domain?

Easy
10

An administrator needs to restrict a user's ability to see only rows where the 'Region' column is 'North'. What feature should be used?

Medium
11

An organization must ensure that PII in a legacy SQL Server database is masked before being accessed by the HR analytics team. Which SQL Server feature should the DBA implement to ensure the data is obscured at the query level without changing the underlying storage?

Medium
12

Which protocol should be enforced for all data-in-transit between application servers and database instances?

Medium
13

A company requires that all database backups be immutable for 7 years to meet regulatory audits. How can this be achieved?

Hard
14

A company needs to implement centralized identity management for all database administrators. Which service is appropriate?

Medium
15

A data engineer is configuring an S3 bucket to comply with GDPR requirements regarding the 'Right to be Forgotten.' Which combination of configuration settings best automates the lifecycle of user-specific data objects that have reached the end of their retention period?

Hard
16

When decommissioning a legacy server, what is the most secure way to handle the hard drives containing sensitive data?

Hard
17

Which TWO controls are necessary to maintain the integrity of a data warehouse?

Hard
18

Which THREE actions should be performed during a data incident response procedure involving a potential PII leak?

Hard
19

When assessing data privacy compliance, which THREE categories of data are typically protected under laws like CCPA or GDPR?

Easy
20

Which THREE of the following are valid methods for securing cloud-based data storage?

Hard
21

A company is migrating to a cloud data warehouse and must comply with CCPA requirements for data portability. Which action is necessary to ensure compliance regarding user access requests?

Medium
22

A database administrator needs to implement column-level encryption for sensitive PII in a SQL Server environment. Which tool should be used to ensure the encryption keys are managed outside the database engine?

Medium
23

A company needs to audit all administrative actions taken on their database server. Which feature should the DBA enable?

Medium
24

Which TWO actions constitute good data lifecycle management?

Medium
25

Which TWO of the following are common administrative tasks in a Data Governance program?

Easy
26

Which type of data is defined as 'sensitive' and usually requires enhanced protection?

Easy
27

Which THREE elements are essential when configuring Database Activity Monitoring (DAM)?

Medium
28

A data analyst discovers that raw log files contain unmasked social security numbers. Which data governance practice should be implemented immediately to remediate the risk?

Medium
29

Which technology provides the best protection against data exfiltration from an on-premises database by a rogue administrator?

Hard
30

An administrator needs to restrict access to a specific S3 bucket so that only the Finance team can view files. Which configuration is the most effective approach?

Easy
31

Which THREE of the following are recognized data governance best practices?

Medium
32

Which document is essential to establish the legal basis for processing personal data under GDPR between a controller and a processor?

Easy
33

As a Data Privacy Officer, you are reviewing technical controls for data security. Which TWO of the following are best practices to ensure 'Privacy by Design' in a new application? (Select TWO)

Medium
34

When reviewing a database security configuration, which finding poses the highest risk?

Medium
35

Which action represents a 'Data Lifecycle' phase where data is safely removed?

Easy
36

To ensure non-repudiation in a database system, what must be captured for every transaction?

Medium
37

What is the first step in a Data Governance program?

Easy
38

What is the primary purpose of a Data Protection Impact Assessment (DPIA) under GDPR?

Easy
39

You are evaluating the data lifecycle of an organization's unstructured data. Which THREE actions should be included in a robust Data Retention and Disposal policy? (Select THREE)

Hard
40

In a multi-tenant cloud database, which mechanism ensures that tenant A cannot see data belonging to tenant B?

Hard
41

Which of the following is a common symptom of a broken access control mechanism in a database?

Medium
42

A security team is implementing an access management strategy. Which THREE of the following are considered essential components of an effective Identity and Access Management (IAM) framework?

Medium
43

An organization uses a 'bring your own key' (BYOK) model for database encryption. What is the primary benefit?

Hard
44

Which TWO technologies or methods are most effective at protecting sensitive data against insider threats?

Hard
45

Which document outlines the 'Data Owner' responsibilities in a data governance framework?

Easy
46

A company is using a cloud-based data lake. To satisfy data sovereignty requirements, they must ensure data remains in a specific region. How can this be enforced?

Hard
47

You are auditing data security controls. You find that raw sensitive data is being written to application logs by the ETL process. Which remediation step best aligns with the principle of 'Data Minimization'?

Medium
48

To comply with CCPA, an organization must track the 'Right to Know' requests. Which component of a Data Governance Framework is most relevant?

Medium
49

An administrator needs to enforce password complexity on the database level. Where should this policy be configured?

Medium

Frequently asked questions

What does the Data Governance And Security domain cover on the DS0-001 exam?
Data Governance And Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 49 Data Governance And Security questions in the DS0-001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Data Governance And Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
comptia-datasys COMPTIA-DATASYS data governance and security Practice Questions