Courseiva
Data Governance →hardMultiple Choice

SF-Data-Arch Data Governance Practice Question

A multinational Salesforce org must ensure that records created in the EU region are stored and processed only within EU-approved infrastructure, while global reporting aggregates anonymized metrics. Which governance control should the architect prioritize to satisfy data residency?

⚠ Common exam trap

The trap here is assuming that encrypting data or restricting record access equals data residency, when residency is determined by where data is stored and processed rather than who can decrypt or view it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the EU data in a Salesforce instance hosted in the EU region and restrict cross-region data flows through integration and sharing design

Data residency requires the records to physically reside and be processed in the approved region, and only anonymized aggregates to cross borders for reporting. Hosting EU data in an EU-region instance with controlled cross-region flows achieves that. Encryption key custody, sharing rules, and authentication each improve security but do not govern the location of storage or processing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Shield Platform Encryption with a tenant secret held by the EU legal entity

    Why it's wrong here

    Customer-managed encryption keys give the EU entity control over decryption and strengthen confidentiality, but they do not change where Salesforce stores or processes the records. Data residency is about location of storage and processing, which key custody alone does not enforce for global reporting paths.

  • ✓

    Deploy the EU data in a Salesforce instance hosted in the EU region and restrict cross-region data flows through integration and sharing design

    Why this is correct

    Data residency is satisfied by hosting the EU records in an EU-region Salesforce instance and controlling how data crosses borders. Restricting cross-region integration and sharing so only anonymized aggregates leave the region directly enforces the requirement while still enabling global reporting.

  • ✗

    Apply record-level sharing rules that limit EU records to EU-based users

    Why it's wrong here

    Sharing rules control which users can access records within an org, but they do not determine where the data physically resides or is processed. A user in another region with access could still trigger processing outside the EU, and the records themselves remain in the same instance.

  • ✗

    Enable Multi-Factor Authentication for all EU users to protect access to regulated records

    Why it's wrong here

    Multi-Factor Authentication strengthens authentication and reduces account compromise risk, but it has no bearing on where data is stored or processed. It is an access-security control rather than a data residency control, so it cannot satisfy the location requirement.

About these practice questions

Courseiva writes every SF-Data-Arch question from scratch — 222 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.