Courseiva
Data Governance →hardMultiple Choice

DA0-002 Data Governance Practice Question

A multinational corporation is implementing a data governance framework. The legal team requires that data stored in the European Union not be transferred to the United States without adequate safeguards. The data engineering team uses a cloud-based data warehouse that replicates data across regions for performance. Which mechanism should the governance team prioritize to ensure compliance with cross-border data transfer requirements?

⚠ Common exam trap

The trap here is assuming that legal frameworks like SCCs or the EU-US Privacy Framework alone are sufficient, when the cloud architecture may still replicate data across regions without technical residency controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing data residency controls that restrict storage and processing of EU personal data to EU regions only.

Data residency controls are the most direct and preventive mechanism because they restrict EU personal data to EU regions, eliminating unauthorized cross-border transfers at the architectural level. This aligns with the legal requirement and avoids reliance on complex legal safeguards that may not fully address automatic replication in a cloud data warehouse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using standard contractual clauses (SCCs) for all data transfers, including intra-company transfers to the US.

    Why it's wrong here

    SCCs are a valid transfer mechanism, but they require legal review and ongoing compliance monitoring. The scenario emphasizes a cloud data warehouse that replicates data across regions, so relying solely on SCCs does not prevent the replication itself. Data residency controls are a more direct and preventive measure for this technical architecture.

  • ✗

    Relying on the EU-US Privacy Framework certification of the cloud provider to cover all transfers.

    Why it's wrong here

    The EU-US Privacy Framework is a valid adequacy mechanism for certified organizations, but it does not automatically cover all transfers, especially if the cloud provider's certification scope does not include the specific data or processing activities. It also does not prevent replication to US regions, so it is not a complete solution for the scenario.

  • ✗

    Encrypting all data with customer-managed keys so that US-based staff cannot decrypt EU data.

    Why it's wrong here

    Encryption with customer-managed keys can protect data confidentiality, but it does not prevent the transfer of encrypted data to the US. The legal requirement is about transfer restrictions, not just access. Moreover, if keys are accessible to US staff, the protection may be insufficient. Data residency is a more comprehensive control.

  • ✓

    Implementing data residency controls that restrict storage and processing of EU personal data to EU regions only.

    Why this is correct

    Data residency controls ensure that EU personal data remains within EU regions, preventing unauthorized cross-border transfers. This directly addresses the legal requirement and is a fundamental governance mechanism for complying with data transfer restrictions. It also simplifies compliance by avoiding the need for complex legal safeguards for transfers.

About these practice questions

This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.