Courseiva
Data Governance →mediumMultiple Choice

SF-Data-Arch Data Governance Practice Question

Northern Trail Outfitters is preparing for a GDPR-driven data subject deletion request affecting a Contact and its related Cases, Email Messages, and custom child records. The architect must ensure the deletion is complete and evidenced. Which approach best satisfies the governance requirement?

⚠ Common exam trap

The trap here is treating a parent record delete or a field-nulling exercise as equivalent to a lawful erasure when related objects and the recycle bin still retain the individual's data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the native Data Subject Request (DSR) tooling to locate, and then erase the individual's data across related objects, capturing the action for evidence

A GDPR erasure request spans every object holding the individual's data, and governance requires proof the action occurred. The native Data Subject Request tooling locates data across related objects, supports erasure, and records the activity, satisfying both completeness and evidence. Manual deletes, field nulling, and off-platform exports each leave residual data or create ungoverned copies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the native Data Subject Request (DSR) tooling to locate, and then erase the individual's data across related objects, capturing the action for evidence

    Why this is correct

    Salesforce provides Data Subject Request tooling that finds an individual's data across related records and supports erasure while producing a record of the action. It addresses the cross-object scope of the request and provides the evidence trail governance requires, unlike a manual delete.

  • ✗

    Export the individual's data to a CSV, delete the Contact, and archive the CSV in a shared drive

    Why it's wrong here

    Exporting the data and storing it in a shared drive does the opposite of erasure by creating a new copy outside governed systems. The CSV is unmanaged, may be retained indefinitely, and provides no reliable evidence that related records in Salesforce were actually removed.

  • ✗

    Overwrite the Contact fields with null values using Data Loader and leave related records intact

    Why it's wrong here

    Nulling fields on the Contact does not erase related Cases, Email Messages, or custom child records, so the individual's data remains in the org. It also leaves no structured evidence that a lawful erasure was performed, which is a governance failure for a GDPR request.

  • ✗

    Delete the Contact record and rely on the recycle bin to remove related records

    Why it's wrong here

    Deleting a parent record cascades to some children, but the recycle bin retains recoverable copies for fifteen days and does not provide the documented, irreversible removal a GDPR erasure request requires. Relying on recycle bin behavior also leaves related objects that are not master-detail children untouched.

About these practice questions

One of 222 original SF-Data-Arch practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.