DA0-002 Data Acquisition and Preparation Practice Question
A financial institution needs to acquire credit transaction data from multiple sources while ensuring compliance with data privacy regulations. What is the most critical step?
⚠ Common exam trap
Candidates often confuse operational efficiency measures (replication, compression) or data enhancement (enrichment) with privacy compliance, overlooking that anonymization must be applied at the earliest point of data acquisition to satisfy regulatory requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data anonymization during extraction
Data anonymization during extraction is the most critical step because it ensures that personally identifiable information (PII) is irreversibly masked or removed before the data enters the processing pipeline, directly addressing compliance with regulations such as GDPR and PCI DSS. Without this step, even if other measures are applied later, the initial exposure of sensitive data violates privacy mandates and increases breach risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data replication for redundancy
Why it's wrong here
Replication copies data for redundancy and availability; it propagates records without checking consent or residency, multiplying compliance exposure. It tempts because resilience matters in finance, but the critical step is governing collection, not duplicating already-acquired data.
- ✗
Data enrichment with external sources
Why it's wrong here
Enrichment adds external attributes after acquisition; it does not itself satisfy privacy obligations. It tempts because richer data improves analytics, but the critical step is consent, lawful basis and masking during collection, so enrichment is a later processing stage.
- ✗
Data compression for storage
Why it's wrong here
Compression reduces storage footprint and cost; it neither governs lawful collection nor protects personal data. It appeals when storage budgets dominate, but the critical step is applying privacy controls at acquisition, and compression can even complicate later redaction.
- ✓
Data anonymization during extraction
Why this is correct
Anonymising data during extraction prevents personal identifiers from entering downstream storage or processing, satisfying privacy regulation requirements at the earliest point. Applying it at extraction rather than later limits exposure and supports purpose limitation and data minimisation obligations.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.