DA0-002 Data Governance Practice Question
A multinational retailer stores customer records in a cloud data warehouse. The governance council must classify each attribute by its sensitivity so downstream masking rules can be applied automatically. The privacy officer asks which classification label should be applied to a field containing government-issued identification numbers that, if exposed, would create legal liability and identity-theft risk.
⚠ Common exam trap
The trap here is assuming any non-public label is sufficient, when the classification tier must reflect the severity of harm rather than merely being internal or confidential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
Government-issued identification numbers create severe personal and legal harm when exposed, which places them in the highest sensitivity tier. The governance council must map each attribute to the tier whose definition matches that worst-case impact so the data warehouse can enforce masking and access rules automatically. Restricted classification drives those strongest controls for every downstream consumer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restricted
Why this is correct
Restricted classification is reserved for the most sensitive data, where exposure causes severe legal, financial, or personal harm. Government-issued identifiers fall into this tier because their disclosure enables identity theft and triggers mandatory breach notification. Labeling the field Restricted ensures the data warehouse enforces the strongest access controls and masking rules automatically for every downstream consumer.
- ✗
Confidential
Why it's wrong here
Confidential data, such as financial projections or employee salaries, requires protection but generally causes business harm rather than identity-theft risk. Government-issued identifiers demand the highest tier because exposure harms the data subject personally and creates legal liability. Choosing Confidential would leave the field one tier below the controls the privacy officer needs.
- ✗
Internal
Why it's wrong here
Internal data is meant only for employees but carries low harm if exposed, such as org charts or internal process documents. Identification numbers cause severe harm when leaked, so Internal understates the risk and would allow broad employee access. The classification tier must match the worst-case impact, and Internal is insufficient for legally protected identifiers.
- ✗
Public
Why it's wrong here
Public data is information intentionally released for unrestricted use, such as marketing brochures or published price lists. Government-issued identification numbers are legally protected and could enable identity theft, so labeling them Public would remove the masking controls the governance council needs and expose the retailer to regulatory penalties and reputational damage under privacy statutes.
Go deeper
Related to this question
About these practice questions
This DA0-002 question is part of Courseiva's 1,004-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.