DA0-002 Data Governance Practice Question
A marketing analyst wants to append a purchased third-party demographic file to the company's customer records. The vendor's contract states the data may be used for internal analytics but not redistributed. Which data governance concept governs how the analyst may lawfully use this dataset?
⚠ Common exam trap
The trap here is conflating data classification with contractual usage rights, when sensitivity labels do not define permitted purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data use agreement, which defines permitted purposes, restrictions, and obligations for the licensed dataset
Licensing and permitted-use questions are governed by data use agreements, which articulate allowable purposes, redistribution prohibitions, and the receiving party's obligations. Classification handles sensitivity, retention handles lifecycle duration, and quality rules handle fitness of values. Only the data use agreement speaks directly to whether the purchased demographic data may be appended and how resulting outputs may be shared.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data use agreement, which defines permitted purposes, restrictions, and obligations for the licensed dataset
Why this is correct
A data use agreement is the contractual instrument that spells out allowable purposes, prohibitions such as redistribution, and the obligations of the receiving party. Because the vendor explicitly limits use to internal analytics and forbids redistribution, the analyst must consult the data use agreement to confirm the append is permitted and to understand downstream sharing limits.
- ✗
Data classification, which labels the dataset as confidential based on sensitivity
Why it's wrong here
Classification assigns sensitivity labels such as public, internal, or restricted to drive handling controls. While the purchased file may carry a classification, classification alone does not express the contractual restriction on redistribution. The analyst needs the usage rights defined by the agreement, not just a sensitivity tier, to determine what is permissible.
- ✗
Data quality rule, which validates that the purchased records meet accuracy thresholds
Why it's wrong here
Quality rules check dimensions such as completeness, accuracy, and timeliness of the data values themselves. They say nothing about legal or contractual permissions. Even a perfectly accurate third-party file may be prohibited from redistribution, so quality validation does not resolve the licensing question the analyst faces.
- ✗
Data retention policy, which specifies how long the records may be stored before deletion
Why it's wrong here
Retention policy dictates storage duration and disposal schedules. It does not address whether the data can be joined to internal records or whether outputs may be shared externally. The vendor's restriction concerns permitted use and redistribution, which is a licensing matter rather than a question of how long the records are kept.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.