DA0-002 Data Governance Practice Question
A hospital analytics team is preparing to share a de-identified patient outcomes dataset with an external research partner. The privacy officer requires that the dataset satisfy governance requirements for lawful secondary use while preserving analytical utility. Which two practices should the team apply? (Choose two.)
⚠ Common exam trap
The trap here is treating de-identification as sufficient on its own, when governance also requires contractual controls that limit purpose, retention, and onward sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove or generalize all direct identifiers such as names, medical record numbers, and full dates of birth.
Lawful secondary use of health data combines de-identification of direct identifiers with a binding data-sharing agreement that scopes purpose, retention, and breach duties. Together they reduce re-identification risk and create enforceable accountability. Unencrypted transfer, indefinite access, and public release each undermine those controls and fail the privacy officer's governance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retain the partner's access indefinitely so future research questions can reuse the dataset.
Why it's wrong here
Indefinite access conflicts with data minimization and retention-limit principles in governance frameworks. Permitted use should be scoped to a defined purpose and time period, after which access is revoked or the data is destroyed. Keeping access open increases exposure and removes the hospital's ability to enforce accountability if the partner's research scope changes.
- ✗
Share the dataset over an unencrypted file transfer so the partner can download it faster.
Why it's wrong here
Unencrypted transfer exposes protected health information in transit to interception and violates security governance requirements for sensitive data. Transfer speed does not justify removing encryption, and the privacy officer's mandate covers both content and transmission. Governance frameworks require encryption in transit for any dataset containing health data, even after de-identification, because residual re-identification risk remains.
- ✓
Remove or generalize all direct identifiers such as names, medical record numbers, and full dates of birth.
Why this is correct
Removing or generalizing direct identifiers reduces re-identification risk and aligns with de-identification expectations for secondary use. Direct identifiers like names and medical record numbers let anyone link records to a person, so they must be stripped or generalized before sharing. This step preserves analytical value in the remaining clinical variables while satisfying the privacy officer's governance requirement.
- ✓
Execute a data-sharing agreement that defines permitted use, retention limits, and breach obligations.
Why this is correct
A data-sharing agreement establishes the legal and governance terms for secondary use, including permitted purposes, retention limits, and breach notification. It gives the hospital contractual leverage if the partner misuses the data and documents the lawful basis for sharing. Without it, the transfer lacks enforceable controls, which the privacy officer requires for external research partnerships.
- ✗
Publish the dataset on a public website to streamline distribution to the research community.
Why it's wrong here
Public release removes all access control and dramatically increases re-identification risk when combined with external datasets. Even de-identified health data can be re-linked through inference attacks, so governance requires controlled distribution to vetted recipients. A public website also conflicts with the data-sharing agreement approach and the privacy officer's mandate for lawful secondary use.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DA0-002 question from scratch — 1,004 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.