SF-Data-Arch · domain
Data Governance
Data Governance on the Salesforce Data Architecture and Management Designer exam covers MDM golden records, data stewardship roles, classification and protection of sensitive data, and Data Governance Council outcomes. Questions are scenario-based: you pick the framework component, steward responsibility, or council goal that best fits a multi-org, auditable enterprise requirement.
Focused practice
Practice Data Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Data Governance
Be able to choose the right MDM, classification, and stewardship approach for a multi-org scenario, and assign each responsibility to the correct role. The single most important thing: governance is policy plus ownership plus enforcement, not just a Salesforce feature.
Selecting MDM patterns that keep a single golden record consistent across Salesforce Orgs and external systems
Data Steward duties: data quality monitoring, metadata and definition ownership, issue remediation, and policy enforcement
Using Data Classification, Shield Platform Encryption, Event Monitoring, and Field Audit Trail for sensitive data categorization, protection, and audit
Data Governance Council goals: policy ownership, cross-functional decision rights, standards, and stewardship accountability
Watch out for
Common Data Governance exam traps
- ▸Treating Data Governance as a one-time project or tool purchase instead of ongoing policy, ownership, and stewardship across Orgs.
- ▸Confusing Data Steward responsibilities with those of the Data Governance Council or executive sponsor, such as budget and enterprise strategy.
- ▸Assuming Shield Platform Encryption or classic audit fields alone satisfy classification, retention, and auditability requirements without governance policy.
Question index
All Data Governance questions (37)
Click any question to see the full explanation, or start a practice session above.
A global insurer is preparing for a data privacy audit. The architect must demonstrate that the Salesforce org can identify where personal data lives and prove who accessed it. Which two capabilities should the architect include in the governance solution? (Choose two.)
Hard2Which governance component ensures that Salesforce Orgs are prepared for major feature updates and potential breaking changes?
Medium3The governance board at a financial services firm wants to know when critical fields on the Opportunity object were changed, who changed them, and what the previous value was, without writing custom code. Which native capability should the architect enable?
Easy4Which strategy best supports Data Governance when scaling a Salesforce implementation across multiple business units with varying data requirements?
Medium5A global Salesforce org has implemented a data governance framework. The governance team needs to ensure that data is retained according to legal and regulatory requirements, and that it is securely deleted when no longer needed. They are evaluating Salesforce's native capabilities for data lifecycle management. Which statement accurately describes a limitation or behavior of Salesforce's native data retention and deletion features that the team must consider?
Hard6A company is defining its Data Stewardship model. Which THREE responsibilities are typically assigned to a Data Steward within a Salesforce-centric data governance framework? (Choose three.)
Medium7An enterprise Salesforce org has multiple business units that each maintain their own picklist values for the Industry field on Account. This has caused inconsistent reporting and integration failures. The Data Governance Council mandates a single, standardized Industry picklist across all business units. Which approach best enforces this standardization while allowing controlled local extensions?
Medium8A global Salesforce org maintains an Account record that is simultaneously updated by an inbound ERP integration, a nightly Data Loader batch, and a sales rep via the Lightning UI. During a data quality audit, the governance board finds that conflicting values for the 'Annual Revenue' field have overwritten each other, and no one can determine which source was authoritative at any point in time. The board wants to ensure that future conflicts are detected, attributed to a source system, and resolved according to a documented priority order before the record is committed. Which governance mechanism should the Data Architect recommend to satisfy this requirement?
Hard9An architect is designing a governance framework for Master Data Management (MDM). Which approach is best for ensuring 'Golden Record' consistency in Salesforce?
Hard10Refer to the exhibit. An organization uses the provided JSON policy to manage PII fields. As a Data Architect, what is the primary governance risk if this policy is not integrated with Salesforce's internal security controls?
Medium11Universal Containers needs to establish a formalized Data Governance framework to manage customer data across multiple Salesforce orgs and external systems. Which foundational element must the Data Governance board define first to ensure enterprise-wide alignment and accountability?
Medium12A healthcare organization is building a data governance program for its Salesforce org. The compliance officer wants a documented record of who owns each data domain, what the approved data definitions are, and how changes to those definitions are approved. Which artifact should the architect establish as the authoritative source for this information?
Easy13Refer to the exhibit. As a Data Architect, what is the governance concern if this 'VAL-099' rule remains inactive in production?
Hard14Northern Trail Outfitters has a Salesforce org where the Account object contains 40 custom fields, many of which were created by different teams over five years. No one is certain which fields are actively used, which are populated by integrations, and which are safe to remove. The CIO asks the data architect to establish ongoing visibility into field usage and data provenance. Which approach best addresses this governance gap?
Hard15A Salesforce org is implementing a data governance program to manage data quality for a large volume of customer records. The architect must recommend tools and features to monitor and improve data quality on an ongoing basis. Which two Salesforce features should be used to proactively identify and address data quality issues? (Choose two.)
Hard16A retail company wants to ensure that customer email addresses are consistently formatted and that invalid values are rejected at the point of entry across web, mobile, and integration channels. The data governance lead asks the architect which Salesforce feature provides a single, reusable definition of the validation that all channels can share. Which feature should the architect recommend?
Easy17A multinational manufacturer runs a single Salesforce org for sales and service. Its governance team wants to enforce that all new custom objects created in production carry a business owner, a retention classification, and a data sensitivity label. Administrators frequently create objects ad hoc, and the team wants an automated check rather than a manual review. Which approach should the data architect recommend?
Medium18Which document is essential to provide to a regulator to prove that the Data Governance program is active and effective?
Medium19A multinational company uses Salesforce across multiple regions. Each region has its own data retention requirements: the EU requires customer data to be deleted after 7 years, while the US requires retention for 10 years. The company wants to implement a data lifecycle governance policy that automatically enforces these retention periods. Which solution should the data architect recommend?
Medium20A Data Architect is tasked with ensuring Data Lifecycle Management is governed. Which lifecycle stage should include a requirement for automated data archiving?
Medium21A Salesforce org has a data governance policy that requires all new custom objects and fields to be reviewed and approved by a data governance council before creation. A developer needs to add a new field to the Account object to support a critical business process. What should the developer do first?
Easy22A healthcare organization uses Salesforce to manage patient cases and must comply with HIPAA. The data governance team needs to ensure that audit trails for access to Protected Health Information (PHI) are comprehensive and tamper-evident. They are evaluating Salesforce Shield Event Monitoring and Field Audit Trail. Which combination of features should the team implement to meet the requirement for tracking who accessed PHI fields and when, while also retaining the audit data for 10 years?
Hard23A large enterprise is struggling with inconsistent data quality across multiple business units. They want to establish a Data Governance Council. Who should lead this council to ensure the initiative receives adequate executive sponsorship and alignment with corporate strategy?
Medium24An organization is establishing a Data Governance Council. Which THREE outcomes are primary goals of this council? (Choose Three)
Hard25Universal Containers maintains a single Salesforce org used by sales teams across North America, EMEA, and APAC. Each region has its own legal requirements for how long personal data may be retained. The VP of Sales wants one consistent retention policy applied everywhere to simplify administration. As the data architect, what should you recommend?
Medium26Northern Trail Outfitters is preparing for a GDPR-driven data subject deletion request affecting a Contact and its related Cases, Email Messages, and custom child records. The architect must ensure the deletion is complete and evidenced. Which approach best satisfies the governance requirement?
Medium27Which document is the most critical for Data Governance to ensure that Salesforce Orgs remain compliant with regional data residency requirements?
Medium28What is the primary role of a Data Dictionary in a Data Governance program?
Medium29A Salesforce org has a data governance policy that requires all new custom objects to have a description and a data owner assigned before deployment to production. The architect needs to enforce this policy automatically during the development lifecycle. Which approach should the architect take?
Medium30A multinational Salesforce org must ensure that records created in the EU region are stored and processed only within EU-approved infrastructure, while global reporting aggregates anonymized metrics. Which governance control should the architect prioritize to satisfy data residency?
Hard31Universal Containers is building a Data Governance program for its Salesforce org. The governance lead wants a single authoritative reference that defines every custom object and field, its business definition, data owner, allowed values, and system of record. Which artifact should the architect recommend as the foundation?
Medium32A multinational financial services company uses Salesforce to manage customer interactions. Its data governance team must ensure that all data elements containing Personally Identifiable Information (PII) are consistently classified, protected, and auditable across Production and Full Sandbox environments. The team is considering using Salesforce Data Mask to anonymize PII in Full Sandboxes. However, they are concerned that masking might alter the original data in Production. What is the most accurate statement regarding Data Mask and its role in this governance strategy?
Medium33A retail company is implementing a data governance program and needs to define ownership and accountability for data quality. The company has multiple business units, each using Salesforce differently. The governance team wants to ensure that each data domain (e.g., Customer, Product, Order) has a clear owner responsible for data quality, definitions, and issue resolution. Which role should be assigned to fulfill this responsibility?
Easy34A firm is implementing a data stewardship program. Which TWO activities are primary responsibilities of a Data Steward? (Choose Two)
Hard35A global organization requires that sensitive customer data be categorized, protected, and auditable across Salesforce Orgs. Which data governance framework component is most effective for ensuring consistent data classification policies?
Medium36A financial services company must retain Salesforce records for seven years to satisfy a regulator. Records older than two years are rarely accessed but must remain retrievable within 48 hours if requested. The org's data volume is growing 40 percent per year, and the architect wants to minimize storage cost while preserving the ability to restore records with their original Salesforce IDs and relationships. Which approach best meets these requirements?
Hard37A financial services firm is implementing Salesforce and must ensure PII data is managed according to strict regional privacy regulations. Which data governance framework component is most essential for tracking data lifecycle stages from collection to deletion?
MediumOther domains
All SF-Data-Arch exam domains
Frequently asked questions
- What does the Data Governance domain cover on the SF-Data-Arch exam?
- Be able to choose the right MDM, classification, and stewardship approach for a multi-org scenario, and assign each responsibility to the correct role. The single most important thing: governance is policy plus ownership plus enforcement, not just a Salesforce feature.
- How many questions are in this domain?
- This page lists all 37 Data Governance questions in the SF-Data-Arch question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.