Courseiva

DA0-002 Visualization and Reporting Practice Question

A data analyst is preparing a report on customer satisfaction scores. To comply with GDPR, which THREE actions must be taken? (Select THREE.)

⚠ Common exam trap

DA0-002 often tests the misconception that 'aggregated data is automatically anonymous' or that retaining data indefinitely is acceptable for analytics — both violate GDPR's storage limitation and anonymization standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure aggregates do not identify individuals

Option B is correct because GDPR's data minimization and purpose-limitation principles require that aggregated statistics used for reporting must not allow re-identification of any individual, so ensuring aggregates do not identify individuals protects data subjects' privacy. Option D is correct because anonymizing personally identifiable information (PII) such as names, email addresses, and account numbers removes the personal data from scope of GDPR processing, satisfying the regulation's requirement to protect identifiable data. Option E is correct because GDPR Article 5(1)(e) mandates storage limitation, meaning the analyst must establish defined data retention periods for the report data rather than keeping it longer than necessary. Option A is incorrect because retaining data indefinitely violates the GDPR storage-limitation principle. Option C is incorrect because including customer names for context unnecessarily introduces identifiable personal data, contradicting data minimization and the anonymization requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retain data indefinitely for analysis

    Why it's wrong here

    Indefinite retention breaches the GDPR storage-limitation principle, which requires personal data be kept no longer than necessary for its stated purpose. It is tempting because long retention supports historical trend analysis, and it would be acceptable only where a documented legal or regulatory obligation specifies that retention period.

  • ✓

    Ensure aggregates do not identify individuals

    Why this is correct

    Aggregation must not allow re-identification, so ensuring aggregates do not identify individuals upholds GDPR's anonymisation principle. It satisfies the compliance constraint by preventing small cell sizes or unique combinations from exposing a single data subject within the satisfaction report.

  • ✗

    Include customer names for context

    Why it's wrong here

    Including customer names exceeds the data-minimisation principle: satisfaction reporting needs only the scores, not directly identifying personal data. It is tempting because names give context and aid interpretation, and it would be justified only where identity is genuinely necessary and a lawful basis plus appropriate safeguards exist.

  • ✓

    Anonymize personally identifiable information

    Why this is correct

    Anonymising personally identifiable information removes the link between data subjects and their satisfaction scores, satisfying GDPR's data minimisation and purpose limitation requirements. This directly addresses the compliance constraint by ensuring the report contains no personal data requiring lawful basis.

  • ✓

    Establish data retention periods for the report data

    Why this is correct

    Establishing retention periods satisfies GDPR's storage limitation principle, which requires personal data be kept no longer than necessary for its stated purpose. For customer satisfaction scores, this means defining and enforcing a deletion schedule, ensuring the report data is not retained indefinitely beyond its lawful analytical use.

About these practice questions

One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.