DA0-002 Data Governance Practice Question
A data governance council at an insurance company is reviewing an incident in which an analyst exported a customer dataset to a personal cloud drive. The council wants a control that detects and blocks sensitive data leaving the managed environment regardless of which application initiates the transfer. Which control type should the council implement?
⚠ Common exam trap
The trap here is equating access control or encryption with exfiltration prevention, when neither monitors or blocks outbound transfers initiated by an authorized user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data loss prevention policies enforced on endpoints and network egress
Detecting and blocking sensitive data leaving the managed environment requires content-aware inspection at the points where data exits, which is the role of data loss prevention on endpoints, email, and network egress. Access control, encryption at rest, and retention schedules address different risks and cannot stop a user from exporting data during an active session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control applied to the data warehouse
Why it's wrong here
Role-based access control governs who can query data inside the warehouse, but it does not monitor or block transfers once data leaves that system. The incident involved movement to a personal cloud drive outside the warehouse, so warehouse-level roles would not detect or prevent the export. The council needs a control that follows the data across applications.
- ✗
Column-level encryption of the customer dataset at rest
Why it's wrong here
Encryption at rest protects data if storage media is stolen, but an authorized analyst can still decrypt and export plaintext to an external drive. The incident was not a storage breach; it was an outbound transfer by a user with legitimate access. Encryption at rest therefore does not detect or block the exfiltration path the council is trying to close.
- ✗
A data retention schedule that deletes customer records after seven years
Why it's wrong here
Retention schedules limit how long data is kept but have no effect on real-time transfers. A record well within its retention window can still be exported to a personal drive. Retention is a lifecycle control, not an egress control, so it cannot satisfy the council's requirement to detect and block sensitive data leaving the environment.
- ✓
Data loss prevention policies enforced on endpoints and network egress
Why this is correct
Data loss prevention inspects content and context on endpoints, email, and network egress to detect and block sensitive data leaving the managed environment, regardless of the initiating application. This matches the council's requirement to catch exports to personal cloud drives. DLP can identify regulated data patterns and stop the transfer or alert security teams in real time.
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.