DA0-002 Data Governance Practice Question
A financial services firm stores customer account records in a relational database. An analyst must assign a classification label to a new table containing Social Security numbers, account balances, and transaction histories. The firm's data governance policy defines four tiers: Public, Internal, Confidential, and Restricted. Which classification tier is most appropriate for this table?
⚠ Common exam trap
The trap here is assuming that because the data belongs to the firm and stays internal, the Internal tier suffices, ignoring that regulated personal identifiers demand the highest protection level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
Social Security numbers combined with account balances and transaction histories represent the most sensitive category of data the firm handles. The highest classification tier exists precisely for regulated identifiers and financial records whose disclosure triggers legal penalties and identity theft risk. Assigning Restricted ensures the table receives maximum access controls, encryption, and audit monitoring consistent with the governance policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confidential
Why it's wrong here
Confidential classification typically protects sensitive business information like strategic plans or proprietary algorithms. Although more restrictive than Internal, it does not specifically address regulated personal identifiers. Social Security numbers combined with financial records trigger the highest tier because unauthorized disclosure creates identity theft risk and mandatory breach notification obligations.
- ✗
Internal
Why it's wrong here
Internal classification covers data intended only for employees, such as org charts or internal procedures. While Internal restricts external sharing, it does not impose the strict access controls, encryption, and audit logging required for personally identifiable financial data. Social Security numbers demand stronger protections than an Internal label provides under the firm's four-tier governance model.
- ✗
Public
Why it's wrong here
Public classification applies to data approved for unrestricted release, such as published marketing materials or open datasets. Social Security numbers and account balances are legally protected and would cause severe harm if disclosed. Labeling this table Public violates the firm's governance policy and would expose the organization to regulatory penalties under GLBA and state privacy laws.
- ✓
Restricted
Why this is correct
Restricted is the highest classification tier, reserved for data whose exposure causes severe legal, financial, or reputational harm. Social Security numbers are regulated personally identifiable information, and combining them with account balances and transaction histories amplifies risk. This table therefore requires the strictest access controls, encryption, and monitoring that the Restricted tier mandates.
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.