SF-Data-Arch Data Governance Practice Question
A multinational Salesforce org must ensure that records created in the EU region are stored and processed only within EU-approved infrastructure, while global reporting aggregates anonymized metrics. Which governance control should the architect prioritize to satisfy data residency?
⚠ Common exam trap
The trap here is assuming that encrypting data or restricting record access equals data residency, when residency is determined by where data is stored and processed rather than who can decrypt or view it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the EU data in a Salesforce instance hosted in the EU region and restrict cross-region data flows through integration and sharing design
Data residency requires the records to physically reside and be processed in the approved region, and only anonymized aggregates to cross borders for reporting. Hosting EU data in an EU-region instance with controlled cross-region flows achieves that. Encryption key custody, sharing rules, and authentication each improve security but do not govern the location of storage or processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Shield Platform Encryption with a tenant secret held by the EU legal entity
Why it's wrong here
Customer-managed encryption keys give the EU entity control over decryption and strengthen confidentiality, but they do not change where Salesforce stores or processes the records. Data residency is about location of storage and processing, which key custody alone does not enforce for global reporting paths.
- ✓
Deploy the EU data in a Salesforce instance hosted in the EU region and restrict cross-region data flows through integration and sharing design
Why this is correct
Data residency is satisfied by hosting the EU records in an EU-region Salesforce instance and controlling how data crosses borders. Restricting cross-region integration and sharing so only anonymized aggregates leave the region directly enforces the requirement while still enabling global reporting.
- ✗
Apply record-level sharing rules that limit EU records to EU-based users
Why it's wrong here
Sharing rules control which users can access records within an org, but they do not determine where the data physically resides or is processed. A user in another region with access could still trigger processing outside the EU, and the records themselves remain in the same instance.
- ✗
Enable Multi-Factor Authentication for all EU users to protect access to regulated records
Why it's wrong here
Multi-Factor Authentication strengthens authentication and reduces account compromise risk, but it has no bearing on where data is stored or processed. It is an access-security control rather than a data residency control, so it cannot satisfy the location requirement.
About these practice questions
Courseiva writes every SF-Data-Arch question from scratch — 222 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.