DA0-002 Data Governance Practice Question
A financial services firm classifies its datasets into public, internal, confidential, and restricted tiers. A data engineer requests access to a restricted customer transaction dataset to build a fraud model. Which combination of controls best enforces the governance policy for this request?
⚠ Common exam trap
The trap here is treating a single control, such as masking or a signed acknowledgment, as sufficient enforcement for restricted data when the classification actually requires layered, attributable access controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply role-based access with least privilege, time-bound approval, and query-level audit logging
Restricted data demands defense in depth: authorization tied to a legitimate purpose, permissions scoped to the individual, a defined expiry, and records that attribute every query. Role-based access with least privilege supplies the scoping, time-bound approval removes standing access after the project, and audit logging makes usage reviewable. Controls that only document intent, share broad roles, or open masked copies each leave an enforcement gap for the highest sensitivity tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant permanent read access after the engineer signs an acceptable use policy acknowledgment
Why it's wrong here
An acknowledgment documents accountability but does not enforce least privilege or time-bound access. Permanent read access to restricted data exceeds what the fraud-modeling purpose requires and persists after the project ends. Because restricted tiers demand stronger technical controls than attestation alone, this approach leaves standing access that governance policy intends to prevent.
- ✓
Apply role-based access with least privilege, time-bound approval, and query-level audit logging
Why this is correct
This combination enforces the restricted tier through layered controls: role-based access scopes permissions to the fraud-modeling function, least privilege limits the data to what the task needs, time-bound approval prevents standing access, and audit logging provides attributable accountability. Together they satisfy both the protective and evidentiary expectations that governance policy places on the most sensitive classification.
- ✗
Mask all customer identifiers in the dataset and allow self-service access to the masked copy
Why it's wrong here
Masking reduces sensitivity but self-service access still bypasses purpose limitation, approval, and accountability for restricted data. Fraud modeling may also require identifiers that masking removes, undermining the project. Because the classification demands controlled, approved, attributable access rather than open access to a modified copy, this option does not enforce the policy.
- ✗
Require manager approval, then grant access through a role shared by the entire analytics department
Why it's wrong here
Approval establishes authorization, but a shared department role violates least privilege by granting restricted data to engineers who have no fraud-modeling need. Shared roles also weaken auditability because activity cannot be attributed to the requesting individual. The policy for restricted data calls for scoped, attributable access, which a broad shared role does not deliver.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.