DA0-002 Visualization and Reporting Practice Question
A data analyst is preparing a dashboard that will be embedded in a public-facing web page and refreshed nightly. The source system contains customer names and account numbers, but the dashboard only needs aggregated counts by region and product line. Which two practices should the analyst apply to reduce disclosure risk while keeping the dashboard functional? (Choose two.)
⚠ Common exam trap
The trap here is assuming that hiding identifier columns in the chart configuration is equivalent to removing them from the data, when the fields still travel to the client.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Suppress or combine aggregate cells whose counts fall below a minimum group size threshold.
Minimizing the dataset to only the fields the dashboard consumes removes direct identifiers at the source, and enforcing a minimum group size on aggregate cells blocks the inference route where a tiny count can single out an individual. Together they let regional and product-line counts be published on a public page while removing the two most common re-identification paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict the dashboard to authenticated internal users so the public page shows a login prompt instead of the report.
Why it's wrong here
Requiring authentication contradicts the stated requirement that the dashboard appear on a public-facing web page, effectively abandoning the delivery channel rather than securing it. It also does not address the underlying issue that unnecessary identifiers are present in the dataset. The scenario asks how to keep the public dashboard functional while lowering disclosure risk, which access restriction does not accomplish.
- ✗
Embed the full source table in the page and rely on the chart configuration to display only aggregated values.
Why it's wrong here
Shipping the full table to the browser means identifiers travel to every visitor, where they can be recovered from network traffic or client-side state regardless of what the chart renders. Visual configuration is a presentation choice, not an access control. This approach maximizes exposure precisely where the scenario demands minimization, and it also inflates payload size for a dashboard that only needs counts.
- ✗
Obscure the identifiers by applying a simple substitution cipher to the name and account number columns before publishing.
Why it's wrong here
Reversible obfuscation still carries the identifying information and can be undone by anyone who obtains the key or guesses the mapping from context. Because the dashboard does not need those columns at all, encrypting them adds risk and complexity with no analytic benefit. True de-identification for this use case means removal, not transformation, of fields the report never consumes.
- ✓
Suppress or combine aggregate cells whose counts fall below a minimum group size threshold.
Why this is correct
Small-count cells are the classic re-identification vector: a region and product line with one or two customers can effectively name those individuals even without a name column. Enforcing a minimum group size, or collapsing sparse cells into an 'other' bucket, preserves the analytic value of large groups while removing the disclosure risk. This complements field removal because it protects against inference from the aggregates themselves.
- ✓
Remove the customer name and account number fields from the dataset feeding the dashboard, since only aggregates are required.
Why this is correct
Data minimization removes direct identifiers that the dashboard never uses, so even a misconfigured visual or an exported underlying dataset cannot expose them. Because the required output is regional and product-line counts, the identifiers contribute nothing to the analysis. Dropping them at the source is more reliable than relying on visual-level hiding, which can be bypassed by users who can access the dataset.
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.