DA0-002 Data Acquisition and Preparation Practice Question
A company is acquiring social media data via a public API. Which TWO considerations are important for ensuring ethical and legal compliance?
⚠ Common exam trap
A common mix-up: candidates confuse 'caching for efficiency' (Option D) with ethical compliance, overlooking that indefinite storage violates data minimization principles and platform terms, while 'internal analysis' (Option B) seems harmless but ignores explicit usage restrictions in the API's terms of service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anonymize personal identifiable information (PII) before storage
Option C is correct because anonymizing personally identifiable information (PII) before storage reduces privacy risk and helps satisfy data-protection regulations such as GDPR and CCPA, which require limiting the processing and retention of identifiable personal data. Option E is correct because a public API is governed by the platform's terms of service, and using the data outside those contractual permissions—such as for prohibited purposes or beyond rate limits—can constitute a legal and ethical violation. Options A and B are not appropriate because sharing raw data with third parties or using it for unrestricted internal analysis can breach privacy obligations and the API's usage terms. Option D is also incorrect because caching data indefinitely conflicts with data-minimization and retention-limitation principles and may violate the platform's terms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share raw data with third parties for additional insights
Why it's wrong here
Sharing raw data with third parties breaches the API's transfer restrictions and consent scope, exposing personal data without a lawful basis. It is tempting because partners may add insight, but ethical compliance demands anonymisation or explicit consent before any onward disclosure.
- ✗
Use the data for any internal analysis without restrictions
Why it's wrong here
Using data for any internal analysis ignores purpose limitation and consent terms in the API agreement, breaching GDPR and platform policies. It is tempting because internal use feels low-risk, but ethical compliance requires restricting processing to the disclosed, consented purpose.
- ✓
Anonymize personal identifiable information (PII) before storage
Why this is correct
Social media data routinely contains personal identifiers, so anonymising PII before storage limits re-identification risk and supports privacy regulation compliance. Removing or masking identifiers at ingestion satisfies the ethical and legal requirement to protect data subjects throughout the acquisition pipeline.
- ✗
Cache data indefinitely to avoid repeated API calls
Why it's wrong here
Caching indefinitely conflicts with API retention limits and data-minimisation duties, and stale personal data breaches storage-limitation principles. It is tempting because it cuts API calls and cost, but lawful caching must honour the platform's terms and defined retention periods.
- ✓
Comply with the platform's terms of service
Why this is correct
Public APIs are governed by contractual terms specifying permitted collection, storage and redistribution of data. Adhering to those terms satisfies the legal compliance requirement, since breaching them can trigger account suspension, contractual liability and regulatory scrutiny regardless of the data's public visibility.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.