Courseiva
Data Governance →hardMultiple Choice

DA0-002 Data Governance Practice Question

A financial services firm classifies its datasets into public, internal, confidential, and restricted tiers. A data engineer requests access to a restricted customer transaction dataset to build a fraud model. Which combination of controls best enforces the governance policy for this request?

⚠ Common exam trap

The trap here is treating a single control, such as masking or a signed acknowledgment, as sufficient enforcement for restricted data when the classification actually requires layered, attributable access controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply role-based access with least privilege, time-bound approval, and query-level audit logging

Restricted data demands defense in depth: authorization tied to a legitimate purpose, permissions scoped to the individual, a defined expiry, and records that attribute every query. Role-based access with least privilege supplies the scoping, time-bound approval removes standing access after the project, and audit logging makes usage reviewable. Controls that only document intent, share broad roles, or open masked copies each leave an enforcement gap for the highest sensitivity tier.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant permanent read access after the engineer signs an acceptable use policy acknowledgment

    Why it's wrong here

    An acknowledgment documents accountability but does not enforce least privilege or time-bound access. Permanent read access to restricted data exceeds what the fraud-modeling purpose requires and persists after the project ends. Because restricted tiers demand stronger technical controls than attestation alone, this approach leaves standing access that governance policy intends to prevent.

  • ✓

    Apply role-based access with least privilege, time-bound approval, and query-level audit logging

    Why this is correct

    This combination enforces the restricted tier through layered controls: role-based access scopes permissions to the fraud-modeling function, least privilege limits the data to what the task needs, time-bound approval prevents standing access, and audit logging provides attributable accountability. Together they satisfy both the protective and evidentiary expectations that governance policy places on the most sensitive classification.

  • ✗

    Mask all customer identifiers in the dataset and allow self-service access to the masked copy

    Why it's wrong here

    Masking reduces sensitivity but self-service access still bypasses purpose limitation, approval, and accountability for restricted data. Fraud modeling may also require identifiers that masking removes, undermining the project. Because the classification demands controlled, approved, attributable access rather than open access to a modified copy, this option does not enforce the policy.

  • ✗

    Require manager approval, then grant access through a role shared by the entire analytics department

    Why it's wrong here

    Approval establishes authorization, but a shared department role violates least privilege by granting restricted data to engineers who have no fraud-modeling need. Shared roles also weaken auditability because activity cannot be attributed to the requesting individual. The policy for restricted data calls for scoped, attributable access, which a broad shared role does not deliver.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.