A global insurer is preparing for a data privacy audit. The architect must demonstrate that the Salesforce org can identify where personal data lives and prove who accessed it. Which two capabilities should the architect include in the governance solution? (Choose two.)
Data Classification lets administrators tag fields with data sensitivity and compliance categories, producing a searchable inventory of where personal data resides. Auditors can then see which fields are classified as personal without manually inspecting every object. This directly supports the requirement to identify where personal data lives across the org.
Why this answer
The audit asks two distinct questions: where personal data resides and who accessed it. Data Classification metadata answers the first by tagging fields with sensitivity categories, and Event Monitoring answers the second by retaining access and API logs for analysis. Field history, bulk exports, and platform encryption do not provide classification inventory or access evidence.
Exam trap
The trap here is substituting a protective control such as Shield Platform Encryption or field history for the classification and access-evidence controls the audit actually requires.