Courseiva
Data Governance →hardMultiple Choice

DA0-002 Data Governance Practice Question

Exhibit

Refer to the exhibit.
{
  "policy": {
    "data_retention": {
      "customer_transactions": "5 years",
      "employee_records": "7 years",
      "marketing_leads": "2 years"
    },
    "data_sharing": {
      "third_party_vendors": "anonymized only",
      "internal_departments": "as needed"
    },
    "data_quality": {
      "missing_values": "flag and report",
      "outliers": "review quarterly"
    }
  }
}

Refer to the exhibit. A data analyst is creating a report that includes customer transaction data from 6 years ago. According to the policy, what should the analyst do?

⚠ Common exam trap

Test-takers frequently assume data can be retained or modified (e.g., anonymized) if it is valuable for analysis, but the policy strictly prohibits using data beyond its retention period, regardless of its potential value or transformation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exclude the data because it exceeds the retention period

The data retention policy specifies that customer transaction data must be retained for only 5 years. Since the data is from 6 years ago, it exceeds the retention period and must be excluded from the report to comply with data governance and regulatory requirements. Including or modifying such data would violate policy and potentially expose the organization to legal or compliance risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anonymize the data before inclusion

    Why it's wrong here

    Anonymisation preserves the record for analysis, but the policy requires disposal of data past its retention period, not de-identification. Anonymising is the right control when data must remain usable while identifiers are removed, not when retention has expired.

  • ✗

    Flag the data for review

    Why it's wrong here

    Flagging defers the decision rather than resolving it; the policy already dictates the required handling for data beyond its retention period, so escalation is unnecessary. Flagging suits ambiguous cases where no policy clause covers the data.

  • ✓

    Exclude the data because it exceeds the retention period

    Why this is correct

    The retention policy caps how long customer transaction data may be kept, and six-year-old records exceed that limit. Excluding them complies with the stated retention period, avoiding the regulatory and privacy breach that retaining or reporting expired personal data would create.

  • ✗

    Include the data since it is valuable for analysis

    Why it's wrong here

    Retention policy governs how long transaction data may be kept; six-year-old records fall outside it, so inclusion breaches the policy regardless of analytical value. Value justifies inclusion only where no retention limit applies, which is not this scenario.

About these practice questions

One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.