DA0-002 Data Governance Practice Question
A data analyst at a regional bank is asked to share a de-identified customer churn dataset with an external marketing consultancy. Before releasing the data, the analyst must confirm that all direct identifiers such as names, account numbers, and Social Security numbers have been removed. Which data governance concept does this action primarily address?
⚠ Common exam trap
Watch out — candidates often confuse de-identification with data minimization, since both reduce privacy risk but only one specifically involves removing identifiers from data that is being shared.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
De-identification
De-identification focuses on removing or obscuring direct identifiers so that individuals are no longer readily identifiable. Stripping names, account numbers, and Social Security numbers from the churn dataset before sharing it with an external consultancy is a textbook example of this practice, making it the governance concept that directly matches the described action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data minimization
Why it's wrong here
Data minimization means collecting and retaining only the data actually needed for a stated purpose, which reduces risk but does not specifically describe stripping names and account numbers from a dataset before external release. The scenario is about removing identifying fields, not about limiting collection scope, so minimization is a related privacy principle but not the precise concept being demonstrated here.
- ✗
Data retention
Why it's wrong here
Data retention defines how long data is kept and when it must be purged or archived according to policy or regulation. The scenario does not involve deciding a storage duration or disposal schedule; it involves altering the dataset contents before external transfer. Applying a retention rule would not remove identifiers, so retention is not the concept being applied.
- ✗
Data lineage
Why it's wrong here
Data lineage documents the origin, movement, and transformation history of data across systems. While lineage is useful for auditing where the churn data came from, it does not itself remove names or account numbers. The analyst's action is a content transformation for privacy, not a documentation of data flow, so lineage is not the correct concept.
- ✓
De-identification
Why this is correct
De-identification is the process of removing or obscuring direct identifiers so that individuals cannot be readily identified from the dataset. Removing names, account numbers, and Social Security numbers before sharing with the consultancy is exactly this process, making it the concept that directly matches the analyst's action in the scenario.
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.