DA0-002 Data Governance Practice Question
Exhibit
Refer to the exhibit.
{
"policy": {
"data_retention": {
"customer_transactions": "5 years",
"employee_records": "7 years",
"marketing_leads": "2 years"
},
"data_sharing": {
"third_party_vendors": "anonymized only",
"internal_departments": "as needed"
},
"data_quality": {
"missing_values": "flag and report",
"outliers": "review quarterly"
}
}
}Refer to the exhibit. A data analyst is creating a report that includes customer transaction data from 6 years ago. According to the policy, what should the analyst do?
⚠ Common exam trap
Test-takers frequently assume data can be retained or modified (e.g., anonymized) if it is valuable for analysis, but the policy strictly prohibits using data beyond its retention period, regardless of its potential value or transformation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exclude the data because it exceeds the retention period
The data retention policy specifies that customer transaction data must be retained for only 5 years. Since the data is from 6 years ago, it exceeds the retention period and must be excluded from the report to comply with data governance and regulatory requirements. Including or modifying such data would violate policy and potentially expose the organization to legal or compliance risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anonymize the data before inclusion
Why it's wrong here
Anonymisation preserves the record for analysis, but the policy requires disposal of data past its retention period, not de-identification. Anonymising is the right control when data must remain usable while identifiers are removed, not when retention has expired.
- ✗
Flag the data for review
Why it's wrong here
Flagging defers the decision rather than resolving it; the policy already dictates the required handling for data beyond its retention period, so escalation is unnecessary. Flagging suits ambiguous cases where no policy clause covers the data.
- ✓
Exclude the data because it exceeds the retention period
Why this is correct
The retention policy caps how long customer transaction data may be kept, and six-year-old records exceed that limit. Excluding them complies with the stated retention period, avoiding the regulatory and privacy breach that retaining or reporting expired personal data would create.
- ✗
Include the data since it is valuable for analysis
Why it's wrong here
Retention policy governs how long transaction data may be kept; six-year-old records fall outside it, so inclusion breaches the policy regardless of analytical value. Value justifies inclusion only where no retention limit applies, which is not this scenario.
Go deeper
Related to this question
About these practice questions
One of 1,004 original DA0-002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DA0-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DA0-002 exam.