Courseiva
Data Governance →mediumMultiple Select

DA0-002 Data Governance Practice Question

A data analyst at a healthcare organization is preparing a dataset for analysis that includes patient identifiers. The organization must comply with HIPAA and internal data governance policies. Which two actions should the analyst take to protect patient privacy while enabling analysis? (Choose two.)

⚠ Common exam trap

The trap here is thinking that encryption alone or broad access controls are sufficient, when the core need is to de-identify the data itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replace patient names and Social Security numbers with pseudonyms before sharing the dataset with analysts.

To protect patient privacy while enabling analysis, the analyst should apply de-identification techniques. Masking or removing direct identifiers prevents immediate identification, and pseudonymization further reduces risk by replacing identifiers with codes. Together, these actions support HIPAA compliance and internal governance by minimizing exposed protected health information while preserving data utility for analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Aggregate all patient data into summary statistics before any analysis is performed.

    Why it's wrong here

    Aggregation can be useful for reporting but severely limits the types of analysis possible, such as patient-level trends. It is not always necessary or appropriate. The goal is to enable analysis while protecting privacy, and aggregation may over-restrict the data. Other techniques like pseudonymization are more flexible.

  • ✓

    Replace patient names and Social Security numbers with pseudonyms before sharing the dataset with analysts.

    Why this is correct

    Pseudonymization replaces direct identifiers with artificial identifiers, reducing privacy risk while preserving the ability to link records. It is a recognized HIPAA-safe harbor technique when applied correctly. This allows analysts to work with the data without exposing protected health information directly, supporting both privacy and utility.

  • ✗

    Store the dataset on a shared network drive with read permissions for the entire department.

    Why it's wrong here

    Broad read permissions increase the risk of unauthorized access. Data governance requires limiting access to only those who need it. A shared drive with department-wide access violates least privilege and could lead to a privacy breach. Secure storage with role-based access is necessary.

  • ✓

    Remove or mask direct identifiers such as names, addresses, and phone numbers from the dataset.

    Why this is correct

    Removing or masking direct identifiers is a fundamental de-identification step. It prevents analysts from directly identifying individuals, aligning with HIPAA's Privacy Rule. When combined with other safeguards, it allows analysis on the remaining data. This action directly addresses privacy by eliminating the most obvious identifiers.

  • ✗

    Encrypt the dataset using AES-256 and share the decryption key with all analysts.

    Why it's wrong here

    Encryption protects data at rest and in transit, but sharing the decryption key with all analysts defeats the purpose because they can still access the raw identifiers. It does not minimize the data itself. Encryption is a complementary control, not a substitute for de-identification or access limits.

About these practice questions

One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.