SF-Data-Arch Data Governance Practice Question
A global insurer is preparing for a data privacy audit. The architect must demonstrate that the Salesforce org can identify where personal data lives and prove who accessed it. Which two capabilities should the architect include in the governance solution? (Choose two.)
⚠ Common exam trap
The trap here is substituting a protective control such as Shield Platform Encryption or field history for the classification and access-evidence controls the audit actually requires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Classification metadata on fields, using the Data Classification feature to tag fields as personal or sensitive.
The audit asks two distinct questions: where personal data resides and who accessed it. Data Classification metadata answers the first by tagging fields with sensitivity categories, and Event Monitoring answers the second by retaining access and API logs for analysis. Field history, bulk exports, and platform encryption do not provide classification inventory or access evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Classification metadata on fields, using the Data Classification feature to tag fields as personal or sensitive.
Why this is correct
Data Classification lets administrators tag fields with data sensitivity and compliance categories, producing a searchable inventory of where personal data resides. Auditors can then see which fields are classified as personal without manually inspecting every object. This directly supports the requirement to identify where personal data lives across the org.
- ✗
A nightly Data Loader job that exports all records for offline retention.
Why it's wrong here
Bulk exporting data for offline retention increases the risk of unmanaged copies and does not classify data or prove access. It also creates a security exposure rather than an audit control. This activity works against the privacy objective because it spreads personal data beyond the governed platform.
- ✗
Field History Tracking enabled on every field in the org to record old and new values.
Why it's wrong here
Field History Tracking records changes to field values, not who viewed or exported data. It also has a limit on the number of tracked fields per object, so enabling it everywhere is impractical. It does not answer the audit question about access to personal data, making it the wrong control for this requirement.
- ✓
Event Monitoring with log retention and the ability to analyze LoginEvent and ApiEvent records.
Why this is correct
Event Monitoring captures access and API activity, including who logged in and which records were accessed through the API. Retaining and analyzing these logs provides the audit evidence that personal data was accessed only by authorized users. Together with classification, it proves both where the data lives and who touched it.
- ✗
Enabling Shield Platform Encryption on all text fields to mask values at rest.
Why it's wrong here
Shield Platform Encryption protects data at rest and in some contexts in transit, but it does not produce an inventory of where personal data lives or a record of who accessed it. It is a protective control, not a classification or audit-evidence control. It complements but does not satisfy the two stated audit requirements.
About these practice questions
One of 222 original SF-Data-Arch practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.