DA0-002 Data Governance Practice Question
A data governance committee is reviewing a new analytics project that will combine customer data from a CRM system with clickstream data from a website. The committee must ensure compliance with the organization's data retention policy. Which consideration is most critical when determining the retention period for the combined dataset?
⚠ Common exam trap
The trap here is assuming that you can average or choose the longest retention period, when the correct approach is to apply the most restrictive policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The retention period should comply with the most restrictive policy among all source datasets and any new regulatory requirements.
When datasets are combined, the resulting data must adhere to the most restrictive retention and usage policies of all sources. This is because the combination may create new privacy risks or fall under multiple regulations. The strictest policy ensures that no source's requirements are violated. Therefore, the committee should identify the shortest retention period or the most stringent regulatory mandate and apply that to the combined dataset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The retention period should be set to match the average retention period of the source systems to simplify management.
Why it's wrong here
Averaging retention periods can violate the stricter policy of one source. If one source requires deletion after 30 days and another after 1 year, an average of about 6 months would retain data too long for the first source. This approach is not compliant.
- ✗
The retention period should be based on the longest retention requirement of any source system to avoid losing data.
Why it's wrong here
Basing retention on the longest requirement may violate policies for data that should be deleted sooner. It also ignores the principle that retention should be justified by business or legal need. Over-retention increases risk and storage costs. The combined dataset should follow the strictest applicable requirement, not the longest.
- ✗
The retention period should be determined by the business owner of the new project without regard to source system policies.
Why it's wrong here
The project owner cannot unilaterally set retention without considering legal and regulatory constraints from the source data. Doing so could lead to non-compliance. Retention policies must align with enterprise governance and applicable laws, not just project needs.
- ✓
The retention period should comply with the most restrictive policy among all source datasets and any new regulatory requirements.
Why this is correct
When combining datasets, the resulting dataset inherits the strictest retention and usage constraints from its sources. This ensures compliance with all applicable regulations and internal policies. For example, if one source has a 30-day retention and another has a 1-year retention, the combined dataset must be deleted after 30 days unless a new lawful basis exists.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.