Courseiva

CCNA Sf Data Governance Questions

37 questions · Sf Data Governance topic · All types, answers revealed

1
Multi-Selecthard

A global insurer is preparing for a data privacy audit. The architect must demonstrate that the Salesforce org can identify where personal data lives and prove who accessed it. Which two capabilities should the architect include in the governance solution? (Choose two.)

Select 2 answers
A.Data Classification metadata on fields, using the Data Classification feature to tag fields as personal or sensitive.
B.A nightly Data Loader job that exports all records for offline retention.
C.Field History Tracking enabled on every field in the org to record old and new values.
D.Event Monitoring with log retention and the ability to analyze LoginEvent and ApiEvent records.
E.Enabling Shield Platform Encryption on all text fields to mask values at rest.
AnswersA, D

Data Classification lets administrators tag fields with data sensitivity and compliance categories, producing a searchable inventory of where personal data resides. Auditors can then see which fields are classified as personal without manually inspecting every object. This directly supports the requirement to identify where personal data lives across the org.

Why this answer

The audit asks two distinct questions: where personal data resides and who accessed it. Data Classification metadata answers the first by tagging fields with sensitivity categories, and Event Monitoring answers the second by retaining access and API logs for analysis. Field history, bulk exports, and platform encryption do not provide classification inventory or access evidence.

Exam trap

The trap here is substituting a protective control such as Shield Platform Encryption or field history for the classification and access-evidence controls the audit actually requires.

2
MCQmedium

Which governance component ensures that Salesforce Orgs are prepared for major feature updates and potential breaking changes?

A.Data Classification Policy.
B.Change Management Process.
C.Data Dictionary.
D.Master Data Management (MDM).
AnswerB

Change management provides the rigorous framework necessary for platform testing and deployment. It ensures that updates are reviewed, tested, and approved, which is essential for identifying potential breaking changes before they reach production. Without this, organizations are prone to unexpected issues and downtime during Salesforce's thrice-yearly release cycle.

Why this answer

The Change Management process is critical for handling major updates. It includes impact analysis, sandbox testing, and regression testing. By governing this process, architects ensure that features are validated in a safe environment before production deployment.

This minimizes the risk of system outages, ensures business continuity, and keeps the Salesforce environment stable during the rapid release cadence of the platform.

Exam trap

Candidates often choose 'Release Management' or 'CI/CD' as the governance component, missing that 'Change Management' is the broader framework that governs the impact and risk of those releases.

3
MCQeasy

The governance board at a financial services firm wants to know when critical fields on the Opportunity object were changed, who changed them, and what the previous value was, without writing custom code. Which native capability should the architect enable?

A.Enable Field History Tracking on the selected Opportunity fields
B.Build a Flow that writes a record to a custom log object on every Opportunity update
C.Schedule a nightly Data Loader export of Opportunity records for comparison
D.Create a Workflow Rule that posts to Chatter when Opportunity fields change
AnswerA

Field History Tracking is the native, no-code feature that records changes to selected fields, including the user who made the change, the timestamp, and the old and new values. Enabling it on the chosen Opportunity fields directly answers the governance board's question about when and by whom critical fields changed.

Why this answer

The board wants a native, no-code record of when critical Opportunity fields changed, who changed them, and the prior values. Field History Tracking provides exactly that for selected fields and requires only configuration. Chatter notifications, custom Flow logging, and nightly exports each capture partial or indirect information and cannot deliver a reliable, attributed field-change history.

Exam trap

The trap here is equating real-time notifications or scheduled snapshots with an auditable history, when only Field History Tracking natively stores prior values with user and timestamp attribution.

4
MCQmedium

Which strategy best supports Data Governance when scaling a Salesforce implementation across multiple business units with varying data requirements?

A.Centralized Governance.
B.Decentralized Governance.
C.Federated Governance.
D.Automated Governance.
AnswerC

Federated governance provides a scalable framework that combines central standards with localized execution. It empowers business units to manage their specific domains while staying within an enterprise-aligned policy framework. This flexibility is essential for large organizations to maintain consistency without hindering the speed of business operations and local innovation.

Why this answer

A Federated Data Governance model is best for large, complex organizations. It allows for central oversight and standardized definitions while giving local business units the autonomy to manage their domain-specific data. This balanced approach avoids the bottlenecks of a purely centralized model while preventing the chaos of a decentralized one, ensuring both compliance and business agility at scale.

Exam trap

Candidates often choose purely centralized governance models, failing to recognize that scaling across diverse business units requires balancing local autonomy with overarching central standards.

5
MCQhard

A global Salesforce org has implemented a data governance framework. The governance team needs to ensure that data is retained according to legal and regulatory requirements, and that it is securely deleted when no longer needed. They are evaluating Salesforce's native capabilities for data lifecycle management. Which statement accurately describes a limitation or behavior of Salesforce's native data retention and deletion features that the team must consider?

A.When a record is deleted in Salesforce, it is immediately and permanently removed from all backups and disaster recovery systems, ensuring compliance with right-to-erasure requests.
B.Salesforce automatically archives inactive records to a separate cold storage system after 2 years, and users can retrieve them via a standard API.
C.Salesforce Field Audit Trail can be used to retain field history for up to 10 years, but it does not automatically delete the data after the retention period; manual intervention is required.
D.Salesforce provides a built-in data retention policy engine that automatically deletes records based on custom retention rules without any development.
AnswerC

Field Audit Trail retains field history for up to 10 years, but it does not automatically purge data after the retention period. Organizations must manually delete or archive the history if they need to enforce a retention limit. This is a key limitation to consider when designing data lifecycle governance, as automated deletion is not provided.

Why this answer

Field Audit Trail retains field history for up to 10 years, but it does not automatically delete data after that period. Manual deletion or archiving is required to enforce retention limits. This is a critical limitation for data lifecycle governance, as organizations must implement their own processes to purge data when it is no longer needed, ensuring compliance with legal and regulatory requirements.

Exam trap

The trap here is assuming that Salesforce provides automated retention enforcement or immediate permanent deletion, when in fact manual intervention is often required.

6
Multi-Selectmedium

A company is defining its Data Stewardship model. Which THREE responsibilities are typically assigned to a Data Steward within a Salesforce-centric data governance framework? (Choose three.)

Select 3 answers
A.Managing daily data quality issues and resolving duplicates.
B.Configuring Salesforce Org-wide defaults and sharing rules.
C.Defining data classification and handling standards.
D.Writing APEX triggers to automate data cleanup.
E.Monitoring data compliance and policy adherence.
AnswersA, C, E

Data stewards are responsible for monitoring and remediating data quality issues. This includes identifying duplicates or incomplete records and coordinating cleanup efforts to maintain a single source of truth, ensuring the Salesforce environment remains clean and usable for all downstream business operations and analytics.

Why this answer

Data Stewards act as the bridge between technical implementation and business utility. Their roles involve maintaining data accuracy, defining standards, and acting as the subject matter experts for specific data domains. By focusing on these areas, they ensure that the data stored in Salesforce remains reliable, compliant, and useful for stakeholders.

These actions prevent the degradation of data quality over time and support ongoing compliance with organizational data policies.

Exam trap

Candidates often include 'coding new features' or 'managing server infrastructure' in the steward's responsibilities, confusing the role of a Data Steward with that of a Developer or System Admin.

7
MCQmedium

An enterprise Salesforce org has multiple business units that each maintain their own picklist values for the Industry field on Account. This has caused inconsistent reporting and integration failures. The Data Governance Council mandates a single, standardized Industry picklist across all business units. Which approach best enforces this standardization while allowing controlled local extensions?

A.Use a global picklist value set for the Industry field and allow each business unit to add values only through a formal governance request process that updates the global set.
B.Leave each business unit with its own custom picklist and create a formula field that maps local values to a standardized set for reporting.
C.Replace the Industry field with a text field and rely on a validation rule that checks values against a custom setting maintained by each business unit.
D.Create a single global picklist value set and assign it to the Industry field on Account for all business units, with no ability for local additions.
AnswerA

A global picklist value set ensures a single source of truth for Industry values across all business units, while a formal governance request process provides a controlled path for local extensions. This balances standardization with flexibility, prevents uncontrolled divergence, and keeps reporting and integrations consistent. It directly satisfies the mandate for a standardized field with governed local additions.

Why this answer

The governance council needs one standardized Industry picklist while still permitting controlled local additions. A global picklist value set provides the single source of truth, and a formal request process ensures any new values are reviewed and added centrally. This prevents uncontrolled divergence, keeps integrations and reporting consistent, and gives business units a governed path to request extensions.

Exam trap

The trap here is assuming that standardization requires completely locking down the picklist, when a governed extension process can preserve flexibility without sacrificing consistency.

8
MCQhard

A global Salesforce org maintains an Account record that is simultaneously updated by an inbound ERP integration, a nightly Data Loader batch, and a sales rep via the Lightning UI. During a data quality audit, the governance board finds that conflicting values for the 'Annual Revenue' field have overwritten each other, and no one can determine which source was authoritative at any point in time. The board wants to ensure that future conflicts are detected, attributed to a source system, and resolved according to a documented priority order before the record is committed. Which governance mechanism should the Data Architect recommend to satisfy this requirement?

A.Create a validation rule that blocks updates to Annual Revenue unless the running user has the 'Data Governance' permission set, and grant that permission set only to the ERP integration user.
B.Implement a Master Data Management (MDM) system of record with survivorship rules that encode the source priority order and write the golden record back to Salesforce.
C.Implement a Data Steward review queue using a custom object and a scheduled Flow that asks the data steward to manually approve each conflicting value.
D.Enable Field History Tracking on Annual Revenue and create a report that shows all changes, then distribute the report to the governance board weekly.
AnswerB

An MDM hub with explicit survivorship rules is the only option that both stores the precedence order as governed metadata and applies it deterministically whenever sources disagree. It can stamp the winning source and retain lineage, so the audit can show which system was authoritative at commit time. This directly satisfies detection, attribution, and documented resolution before the record is committed.

Why this answer

The requirement is a governed, deterministic conflict-resolution process that records which source system was authoritative. An MDM system of record with survivorship rules encodes the source priority order as governed metadata, applies it automatically when sources disagree, and preserves lineage for audit. Field history, manual review queues, and permission-based write exclusion either act too late, rely on human latency, or block legitimate writes without resolving the underlying conflict.

Exam trap

The trap here is assuming that field history tracking or a manual approval queue constitutes conflict resolution, when neither encodes a source priority order nor prevents conflicting overwrites from committing.

9
MCQhard

An architect is designing a governance framework for Master Data Management (MDM). Which approach is best for ensuring 'Golden Record' consistency in Salesforce?

A.Using Duplicate Rules to merge records.
B.Implementing an external MDM hub.
C.Creating custom formula fields.
D.Enabling Person Accounts for all users.
AnswerB

An external hub acts as the central authority for master data. It validates, cleanses, and synchronizes the 'Golden Record' across all connected systems, including Salesforce. This approach is superior for enterprise environments where data exists across multiple platforms and needs a single, unified source of truth to maintain data integrity.

Why this answer

A Master Data Management strategy requires a 'Source of Truth' identification. By defining which system holds the primary record and using integration middleware to synchronize these records, the architect creates a consistent 'Golden Record'. This prevents data fragmentation where different systems maintain conflicting versions of the same customer, which is the core challenge MDM aims to solve.

Exam trap

Many candidates choose 'standard Salesforce duplicate rules' as the solution, forgetting that MDM requires a cross-system synchronization strategy, not just internal record matching within a single Salesforce org.

10
MCQmedium

Refer to the exhibit. An organization uses the provided JSON policy to manage PII fields. As a Data Architect, what is the primary governance risk if this policy is not integrated with Salesforce's internal security controls?

A.Increased latency in database query execution.
B.Inconsistent enforcement of privacy compliance.
C.Loss of data due to automated purging.
D.Increased storage consumption in the Org.
AnswerB

When documentation deviates from actual Salesforce security settings, compliance audits will fail. The system becomes vulnerable because the policy exists in a silo, and the technical implementation fails to match the required controls. This inconsistency creates a false sense of security, exposing the organization to legal and regulatory penalties.

Why this answer

The primary risk is the discrepancy between the documented policy and the actual system implementation. If the JSON policy dictates partial masking but the Salesforce configuration allows full view access via profiles or permission sets, the policy becomes ineffective. This gap compromises compliance, as the organization cannot guarantee that data protection rules are actually enforced at the application layer where users interact.

Exam trap

Candidates often select system performance or storage issues as the primary risk, overlooking critical compliance and regulatory failures caused by policy-to-configuration alignment gaps.

11
MCQmedium

Universal Containers needs to establish a formalized Data Governance framework to manage customer data across multiple Salesforce orgs and external systems. Which foundational element must the Data Governance board define first to ensure enterprise-wide alignment and accountability?

A.Implement exact-match duplicate rules across all Salesforce objects.
B.Define data owners, stewards, and organizational policies for critical data domains.
C.Configure Platform Encryption for all Personally Identifiable Information fields.
D.Establish an automated archiving job for records older than seven years.
AnswerB

Defining data owners, stewards and policies for critical data domains establishes the accountability structure the board needs before any technical controls. Without named owners and stewards per domain, cross-org alignment and enforcement cannot be assigned, so this foundational element must precede tooling or standards decisions.

Why this answer

Establishing data ownership and stewardship is the critical first step in any Data Governance framework. Without clearly defined owners responsible for data quality, definitions, and lifecycle policies across disparate systems, subsequent technical implementations like Master Data Management or deduplication rules lack institutional direction and authoritative accountability.

Exam trap

Candidates frequently jump to technical solutions like 'implementing a data warehouse' or 'data cleansing' before establishing the human governance structure of who actually owns and manages the data.

12
MCQeasy

A healthcare organization is building a data governance program for its Salesforce org. The compliance officer wants a documented record of who owns each data domain, what the approved data definitions are, and how changes to those definitions are approved. Which artifact should the architect establish as the authoritative source for this information?

A.A Salesforce report listing all custom objects and their record counts.
B.A set of validation rules that enforce data entry standards on key objects.
C.An integration architecture diagram showing how data flows between Salesforce and external systems.
D.A data governance charter and data dictionary that define domain ownership, approved definitions, and the change-approval workflow.
AnswerD

A governance charter establishes the program's structure, roles, and decision rights, while a data dictionary documents approved definitions and ownership for each data domain. Together they provide the authoritative, auditable record the compliance officer requires, including how definition changes are proposed, reviewed, and approved.

Why this answer

The compliance officer is asking for documented accountability, agreed definitions, and a controlled change process. A governance charter defines the program's roles, decision rights, and approval paths, while a data dictionary records the approved definition and owner for each data domain. Together they form the authoritative governance reference that can be audited and maintained over time.

Exam trap

The trap here is selecting a technical artifact such as a report or validation rule that demonstrates data controls, when the requirement is for documented ownership, definitions, and approval authority.

13
MCQhard

Refer to the exhibit. As a Data Architect, what is the governance concern if this 'VAL-099' rule remains inactive in production?

A.Increased system storage limits.
B.Inability to run system reports.
C.Degradation of data quality over time.
D.Increased Apex trigger execution time.
AnswerC

When an active validation rule is turned off, the system stops checking for input errors. This allows bad data to accumulate, which degrades the quality of the dataset. Over time, this makes it harder to use that data for business intelligence, marketing campaigns, or sales forecasting, leading to untrustworthy results.

Why this answer

The primary concern is the uncontrolled entry of corrupt data. If a governance rule is defined but not active, the system lacks the technical enforcement to maintain quality standards. This leads to 'data rot' where the system collects invalid entries, which will eventually break downstream integrations, analytics reporting, and business processes, causing significant effort for data cleansing at a later date.

Exam trap

Candidates often focus on the immediate technical error, such as 'API failure,' rather than the long-term governance impact of 'data rot' and the resulting degradation of data quality.

14
MCQhard

Northern Trail Outfitters has a Salesforce org where the Account object contains 40 custom fields, many of which were created by different teams over five years. No one is certain which fields are actively used, which are populated by integrations, and which are safe to remove. The CIO asks the data architect to establish ongoing visibility into field usage and data provenance. Which approach best addresses this governance gap?

A.Enable Field Audit Trail on all 40 custom fields and rely on the audit history as the primary source of field usage documentation.
B.Restrict field creation permissions to system administrators and freeze the Account object schema to prevent further sprawl.
C.Run a one-time report on field population rates and delete all fields with less than 10% fill rate.
D.Create a data dictionary and metadata inventory that documents each field's purpose, source system, and owning team, and establish a review cadence to keep it current.
AnswerD

A maintained data dictionary and metadata inventory directly address the gap: they record what each field means, where its data originates, and who owns it. Coupling the artifact with a recurring review cadence ensures the information stays accurate as teams and integrations change. This gives the CIO durable visibility and a basis for future deprecation decisions.

Why this answer

The core issue is a lack of documented knowledge about existing fields and their origins. A data dictionary paired with a metadata inventory captures purpose, source, and ownership for each field, and a review cadence keeps it trustworthy over time. This combination gives leadership the ongoing visibility needed to make informed deprecation and consolidation decisions rather than guessing from a single usage metric.

Exam trap

The trap here is treating a one-time usage metric as sufficient evidence for permanent schema decisions, when governance requires documented provenance and a repeatable review process.

15
Multi-Selecthard

A Salesforce org is implementing a data governance program to manage data quality for a large volume of customer records. The architect must recommend tools and features to monitor and improve data quality on an ongoing basis. Which two Salesforce features should be used to proactively identify and address data quality issues? (Choose two.)

Select 2 answers
A.Duplicate Management with Matching Rules and Duplicate Rules
B.Data Loader with batch size optimization
C.Salesforce Optimizer
D.Validation Rules to enforce data quality at entry
E.Reports and Dashboards with custom report types
AnswersA, D

Duplicate Management allows you to define matching rules to identify duplicate records and duplicate rules to control what happens when duplicates are detected (e.g., alert, block, or allow). This proactively identifies and prevents duplicate data entry, which is a key aspect of data quality. It can be configured for standard and custom objects, and runs in real-time on record creation and edit, as well as via batch jobs for existing data.

Why this answer

Duplicate Management and Validation Rules are proactive features that identify and prevent data quality issues. Duplicate Management detects and manages duplicate records, while Validation Rules enforce data quality at entry by blocking invalid saves. Data Loader, Salesforce Optimizer, and Reports/Dashboards are not proactive data quality tools; they serve other purposes like data loading, org optimization, or monitoring.

Exam trap

The trap here is assuming that reporting tools or data loading tools proactively enforce data quality, when they are passive or manual.

16
MCQeasy

A retail company wants to ensure that customer email addresses are consistently formatted and that invalid values are rejected at the point of entry across web, mobile, and integration channels. The data governance lead asks the architect which Salesforce feature provides a single, reusable definition of the validation that all channels can share. Which feature should the architect recommend?

A.A validation rule on the Contact object using a REGEX function to enforce a standard email pattern.
B.A duplicate rule that matches contacts with similar email addresses.
C.A formula field that concatenates the email domain with a fixed suffix.
D.A record-triggered flow that sends a notification to the data steward when the email is malformed.
AnswerA

Validation rules evaluate on insert and update regardless of channel, so the same REGEX-based rule applies to web, mobile, and integration writes. It provides one reusable definition of the format requirement and blocks invalid values at the point of entry. This directly satisfies the governance lead's request for consistency across all channels.

Why this answer

Validation rules are evaluated on every insert and update no matter which channel performs the write, so a REGEX-based rule gives one reusable definition of the email format standard. It prevents invalid values from being saved, which is what the governance policy requires. Formula fields, duplicate rules, and notification flows either do not validate or act only after the fact.

Exam trap

The trap here is confusing detection or duplication controls with prevention, when the requirement is a shared validation definition that rejects invalid values at entry.

17
MCQmedium

A multinational manufacturer runs a single Salesforce org for sales and service. Its governance team wants to enforce that all new custom objects created in production carry a business owner, a retention classification, and a data sensitivity label. Administrators frequently create objects ad hoc, and the team wants an automated check rather than a manual review. Which approach should the data architect recommend?

A.Enable Field Audit Trail and Field History Tracking on all custom objects to capture who created each object.
B.Build a custom validation rule on each custom object that checks the owner field is populated on records.
C.Use Metadata API and Apex Metadata API to scan object definitions against a governance checklist and block deployment when required attributes are missing.
D.Require every administrator to submit a change request through a ServiceNow workflow before creating a custom object.
AnswerC

Metadata API exposes object definitions, including custom fields, descriptions, and custom metadata values, so a governance service can programmatically evaluate every object against the required attributes. Apex Metadata API allows the check to run inside Salesforce and to fail a deployment or raise an alert. This gives the automated, metadata-level enforcement the governance team asked for.

Why this answer

Metadata-level governance requires inspecting object definitions, which only metadata-aware tooling can do. A programmatic check using Metadata API and Apex Metadata API lets the team compare each object against required attributes such as owner, retention classification, and sensitivity label, and it can fail the deployment automatically. Manual workflows and record-level rules cannot assert anything about the object definition itself.

Exam trap

The trap here is assuming record-level validation rules or change-request workflows can enforce metadata standards, when only metadata-aware tooling can inspect object definitions.

18
MCQmedium

Which document is essential to provide to a regulator to prove that the Data Governance program is active and effective?

A.Data Governance Charter.
B.List of user profiles.
C.Salesforce Developer Guide.
D.Individual user training materials.
AnswerA

The charter is the formal document that defines the governance program's scope, mission, and organizational authority. It is the primary artifact that regulators look for to verify that an organization has officially committed to structured data management and compliance, providing the necessary high-level evidence of a sound governance framework.

Why this answer

The Data Governance Charter is the foundational document that outlines the authority, scope, and objectives of the program. It provides the official mandate, showing that the organization has formally recognized the importance of data governance. For regulators, this is the first proof that the organization has a structured approach to managing data quality, security, and compliance in its systems.

Exam trap

Candidates often confuse strategic framework documents like the Data Governance Charter with operational artifacts like data dictionaries or technical architecture diagrams when proving program compliance to regulators.

19
MCQmedium

A multinational company uses Salesforce across multiple regions. Each region has its own data retention requirements: the EU requires customer data to be deleted after 7 years, while the US requires retention for 10 years. The company wants to implement a data lifecycle governance policy that automatically enforces these retention periods. Which solution should the data architect recommend?

A.Create a custom object to store retention policies and use scheduled Apex to delete records based on region-specific criteria.
B.Rely on the Salesforce recycle bin and set its retention period to 7 years for EU records and 10 years for US records.
C.Use Salesforce Data Retention policies in Setup to define region-specific retention rules and automate deletion.
D.Implement a combination of Salesforce Shield Field Audit Trail for compliance and a custom batch process to archive and purge records according to regional policies.
AnswerD

Field Audit Trail provides long-term retention of field history for compliance, while a custom batch process can enforce region-specific retention by archiving and purging records. This combination addresses both the need for auditability and the requirement to delete data after the specified periods. It allows the company to tailor retention logic per region and maintain a clear audit trail.

Why this answer

The company needs region-specific retention enforcement with auditability. Field Audit Trail retains field history for compliance, while a custom batch process can archive and purge records according to each region's retention period. This approach provides the flexibility to implement different retention rules and maintains an audit trail, unlike native recycle bin or non-existent general retention settings.

Exam trap

The trap here is assuming Salesforce has a built-in data retention policy UI for arbitrary records, when in reality retention requires a combination of audit trail and custom automation.

20
MCQmedium

A Data Architect is tasked with ensuring Data Lifecycle Management is governed. Which lifecycle stage should include a requirement for automated data archiving?

A.Data Creation.
B.Data Usage.
C.Data Retention.
D.Data Acquisition.
AnswerC

Retention governance defines how long data is stored and when it should be moved or archived. Automating this phase ensures that production storage is kept clean and performant. By moving inactive data to archival storage, the organization balances regulatory requirements with the need for a lean, high-performing active Salesforce environment.

Why this answer

The 'Retention' or 'Disposition' phase is where archiving is most critical. As data ages, its value decreases, while storage costs and security risks remain. By governing this stage, the architect ensures that older data is moved to cheaper, secure storage (archiving) rather than being deleted or kept in active production tables, which optimizes system performance and maintains compliance with storage policies.

Exam trap

Candidates often confuse the 'Archiving' stage with 'Data Storage' or 'Database Optimization,' failing to recognize that retention policies specifically dictate the timing and conditions for moving data to cold storage.

21
MCQeasy

A Salesforce org has a data governance policy that requires all new custom objects and fields to be reviewed and approved by a data governance council before creation. A developer needs to add a new field to the Account object to support a critical business process. What should the developer do first?

A.Ask the Salesforce administrator to create the field as a temporary workaround and document it in a technical debt log.
B.Use the Salesforce Setup menu to create the field directly in production, then notify the governance council afterward.
C.Create the field in a sandbox and then submit a change set for deployment to production.
D.Submit a request to the data governance council for review and approval, providing business justification and impact analysis.
AnswerD

The governance policy explicitly requires review and approval by the data governance council before creating new custom objects or fields. Submitting a request with justification and impact analysis is the correct first step. It ensures the council can assess the need, check for redundancy, and maintain data standards. Only after approval should the developer proceed with creation.

Why this answer

The governance policy clearly states that new custom objects and fields must be reviewed and approved before creation. The developer should first submit a request to the data governance council with business justification and impact analysis. This ensures the council can evaluate the request against data standards and avoid unnecessary or redundant fields.

Only after approval should the field be created.

Exam trap

The trap here is focusing on the technical steps of field creation and overlooking the mandatory governance approval process that must occur first.

22
MCQhard

A healthcare organization uses Salesforce to manage patient cases and must comply with HIPAA. The data governance team needs to ensure that audit trails for access to Protected Health Information (PHI) are comprehensive and tamper-evident. They are evaluating Salesforce Shield Event Monitoring and Field Audit Trail. Which combination of features should the team implement to meet the requirement for tracking who accessed PHI fields and when, while also retaining the audit data for 10 years?

A.Use Salesforce Shield Platform Encryption to encrypt PHI fields, which automatically generates audit logs for all access and retains them for 10 years.
B.Enable Field Audit Trail with a retention policy of 10 years, and use Event Monitoring to track field-level access events.
C.Use Event Monitoring alone, as it captures all user activity including field-level changes, and set the retention period to 10 years.
D.Enable Field Audit Trail and configure it to also capture read access events, eliminating the need for Event Monitoring.
AnswerB

Field Audit Trail tracks changes to field values and can retain field history for up to 10 years, meeting the retention requirement. Event Monitoring captures access events, including who viewed or exported data, providing a comprehensive audit trail. Together, they address both change tracking and access tracking for PHI, ensuring HIPAA compliance.

Why this answer

Field Audit Trail provides long-term retention of field history, up to 10 years, and tracks changes to PHI fields. Event Monitoring captures access events, including reads and exports, which are not covered by Field Audit Trail. Together, they deliver a complete audit trail for HIPAA compliance, ensuring both change and access tracking with the required retention.

Exam trap

The trap here is believing that Field Audit Trail captures read access or that Event Monitoring alone can provide 10-year retention, when in fact they serve complementary roles.

23
MCQmedium

A large enterprise is struggling with inconsistent data quality across multiple business units. They want to establish a Data Governance Council. Who should lead this council to ensure the initiative receives adequate executive sponsorship and alignment with corporate strategy?

A.The Lead Salesforce Administrator.
B.The Chief Data Officer or a senior business executive.
C.The Vice President of IT Infrastructure.
D.The external Salesforce Implementation Partner.
AnswerB

A Chief Data Officer or senior executive provides the necessary mandate to enforce governance policies across diverse business units. Their involvement ensures that data governance is treated as a strategic business initiative, securing the executive-level support needed to manage organizational change and resource allocation effectively.

Why this answer

Executive sponsorship is the single most important factor for the success of a Data Governance initiative. By appointing a Chief Data Officer or a senior business leader, the organization signals that data is a strategic asset rather than just an IT concern. This alignment ensures that funding, resources, and cross-departmental cooperation are prioritized, effectively breaking down silos that often impede data quality projects.

Exam trap

Candidates often suggest a 'Lead Data Architect' or 'IT Manager' to lead the council, failing to recognize that governance requires executive authority to enforce changes across business units.

24
Multi-Selecthard

An organization is establishing a Data Governance Council. Which THREE outcomes are primary goals of this council? (Choose Three)

Select 3 answers
A.Resolving data ownership and stewardship conflicts.
B.Setting organization-wide data standards.
C.Managing daily Apex deployment cycles.
D.Fostering data stewardship and accountability.
E.Directly configuring Salesforce security profiles.
AnswersA, B, D

Conflicts often arise regarding who 'owns' a piece of data, leading to inconsistent definitions. The council acts as the final arbiter for these disputes, ensuring that roles are clearly defined and that business units agree on the sources of truth, which is essential for uniform reporting and data usage.

Why this answer

A Data Governance Council is a cross-functional body that aligns data strategy with business objectives. By resolving data ownership conflicts, setting enterprise-wide standards, and fostering communication between business units and IT, the council ensures that data is managed as a strategic asset. This alignment prevents silos, ensures accountability, and maximizes the value derived from data across the entire organization.

Exam trap

Candidates frequently select low-level technical execution tasks like writing ETL scripts, forgetting that a Data Governance Council operates at a strategic, cross-functional policy-setting level.

25
MCQmedium

Universal Containers maintains a single Salesforce org used by sales teams across North America, EMEA, and APAC. Each region has its own legal requirements for how long personal data may be retained. The VP of Sales wants one consistent retention policy applied everywhere to simplify administration. As the data architect, what should you recommend?

A.Retain all personal data indefinitely because Salesforce storage is inexpensive and deletion carries operational risk.
B.Implement a single global retention schedule for all personal data records and document it in the data governance policy.
C.Define region-specific retention rules in the governance policy and enforce them through record segmentation and automated deletion processes.
D.Delegate all retention decisions to regional sales managers and let each team manage its own data without a central policy.
AnswerC

Region-specific retention rules honor each jurisdiction's legal requirements while still operating under a single overarching governance framework. Enforcement requires segmenting records (for example, by region field or record type) and scheduling automated deletion or archival jobs per segment. This satisfies both the compliance mandate and the need for a consistent, documented policy.

Why this answer

Retention requirements that vary by jurisdiction demand a governance policy that encodes those differences rather than flattening them. Segmenting records by region and applying automated retention jobs per segment allows one org to comply with multiple legal regimes. This approach keeps the policy centralized and auditable while respecting local law, which is the core purpose of a data governance framework in a multi-region Salesforce deployment.

Exam trap

The trap here is assuming that a simpler, uniform retention policy is automatically better because it is easier to administer, when legal compliance actually requires differentiated handling by region.

26
MCQmedium

Northern Trail Outfitters is preparing for a GDPR-driven data subject deletion request affecting a Contact and its related Cases, Email Messages, and custom child records. The architect must ensure the deletion is complete and evidenced. Which approach best satisfies the governance requirement?

A.Use the native Data Subject Request (DSR) tooling to locate, and then erase the individual's data across related objects, capturing the action for evidence
B.Export the individual's data to a CSV, delete the Contact, and archive the CSV in a shared drive
C.Overwrite the Contact fields with null values using Data Loader and leave related records intact
D.Delete the Contact record and rely on the recycle bin to remove related records
AnswerA

Salesforce provides Data Subject Request tooling that finds an individual's data across related records and supports erasure while producing a record of the action. It addresses the cross-object scope of the request and provides the evidence trail governance requires, unlike a manual delete.

Why this answer

A GDPR erasure request spans every object holding the individual's data, and governance requires proof the action occurred. The native Data Subject Request tooling locates data across related objects, supports erasure, and records the activity, satisfying both completeness and evidence. Manual deletes, field nulling, and off-platform exports each leave residual data or create ungoverned copies.

Exam trap

The trap here is treating a parent record delete or a field-nulling exercise as equivalent to a lawful erasure when related objects and the recycle bin still retain the individual's data.

27
MCQmedium

Which document is the most critical for Data Governance to ensure that Salesforce Orgs remain compliant with regional data residency requirements?

A.User Access Request Log.
B.Data Inventory and Mapping.
C.Service Level Agreement (SLA).
D.Salesforce Org release notes.
AnswerB

A data inventory maps the flow and storage location of data across the enterprise. It is essential for residency compliance because it identifies where data originates, moves, and resides. Without this, an organization cannot prove to regulators that they are keeping data within the required legal jurisdictions or borders.

Why this answer

The Data Inventory and Mapping document is critical because it identifies exactly where sensitive data resides. To comply with data residency laws, architects must know which Org holds data and where those Orgs are physically hosted. Without this mapping, it is impossible to audit compliance or implement the necessary architectural controls to keep data within specific geographic borders as required by law.

Exam trap

Many respondents pick technical documents like ERDs or security guides, failing to recognize that compliance tracking requires specific data location mapping.

28
MCQmedium

What is the primary role of a Data Dictionary in a Data Governance program?

A.Enforcing record-level security.
B.Establishing a standard metadata definition.
C.Automating data cleaning processes.
D.Managing integration authentication tokens.
AnswerB

The data dictionary serves as the single source of truth for metadata definitions. By standardizing how data is described and used across the organization, it eliminates inconsistencies. This clarity is vital for developers and business users alike, as it ensures they all interpret the data in exactly the same way.

Why this answer

A Data Dictionary acts as a central repository for technical and business metadata. It provides a common language for stakeholders, ensuring that everyone understands what a field represents, its data type, and its business rules. By centralizing this information, the dictionary prevents ambiguity and errors in reporting, which is a fundamental requirement for building a reliable, governed data environment.

Exam trap

Candidates often mistake the Data Dictionary for a 'Data Catalog' or 'Data Warehouse,' overlooking its primary purpose as a centralized repository for metadata definitions and common business language.

29
MCQmedium

A Salesforce org has a data governance policy that requires all new custom objects to have a description and a data owner assigned before deployment to production. The architect needs to enforce this policy automatically during the development lifecycle. Which approach should the architect take?

A.Configure a permission set that only allows users to create custom objects if they include a description.
B.Use a Salesforce CLI plugin or a script in the CI/CD pipeline to check metadata for description and owner before deployment.
C.Create a validation rule on the custom object that requires the description field to be populated.
D.Set up a workflow rule that sends an email to the data governance team when a new custom object is created without a description.
AnswerB

A CI/CD pipeline can run automated checks on metadata using Salesforce CLI or custom scripts. By querying the Metadata API or using tools like SFDX Scanner, you can verify that each custom object has a description and an owner field populated. This enforcement happens before deployment, ensuring compliance with the governance policy. It is a proactive, automated approach that aligns with DevOps best practices.

Why this answer

Enforcing metadata standards like requiring a description and data owner on custom objects requires checking metadata before deployment. A CI/CD pipeline with Salesforce CLI or scripts can automate these checks, preventing non-compliant metadata from being deployed. Validation rules, permission sets, and workflow rules operate on data or user access, not metadata, so they cannot enforce this policy.

Exam trap

The trap here is thinking that declarative Salesforce features like validation rules or workflow rules can enforce metadata requirements, when they only work on record data.

30
MCQhard

A multinational Salesforce org must ensure that records created in the EU region are stored and processed only within EU-approved infrastructure, while global reporting aggregates anonymized metrics. Which governance control should the architect prioritize to satisfy data residency?

A.Configure Shield Platform Encryption with a tenant secret held by the EU legal entity
B.Deploy the EU data in a Salesforce instance hosted in the EU region and restrict cross-region data flows through integration and sharing design
C.Apply record-level sharing rules that limit EU records to EU-based users
D.Enable Multi-Factor Authentication for all EU users to protect access to regulated records
AnswerB

Data residency is satisfied by hosting the EU records in an EU-region Salesforce instance and controlling how data crosses borders. Restricting cross-region integration and sharing so only anonymized aggregates leave the region directly enforces the requirement while still enabling global reporting.

Why this answer

Data residency requires the records to physically reside and be processed in the approved region, and only anonymized aggregates to cross borders for reporting. Hosting EU data in an EU-region instance with controlled cross-region flows achieves that. Encryption key custody, sharing rules, and authentication each improve security but do not govern the location of storage or processing.

Exam trap

The trap here is assuming that encrypting data or restricting record access equals data residency, when residency is determined by where data is stored and processed rather than who can decrypt or view it.

31
MCQmedium

Universal Containers is building a Data Governance program for its Salesforce org. The governance lead wants a single authoritative reference that defines every custom object and field, its business definition, data owner, allowed values, and system of record. Which artifact should the architect recommend as the foundation?

A.A Data Loader field-mapping spreadsheet used for the most recent migration
B.An Entity Relationship Diagram showing all object relationships and cardinalities
C.A Data Dictionary maintained as a versioned document and published to all stakeholders
D.A Field Audit Trail retention policy configured on all custom objects
AnswerC

A Data Dictionary is the authoritative catalog of metadata: object and field names, definitions, owners, allowed values, and system of record. It directly satisfies the governance lead's requirement for one reference covering every field's business meaning and ownership, and it becomes the baseline against which changes are reviewed.

Why this answer

The requirement is one authoritative reference covering field definitions, ownership, allowed values, and system of record. A Data Dictionary is precisely that artifact and is the standard foundation for a Data Governance program. ERDs, audit retention policies, and migration mappings each serve narrower technical purposes and cannot substitute for a maintained catalog of business and technical metadata.

Exam trap

The trap here is assuming any metadata documentation, such as an ERD or a migration mapping, satisfies governance when only a maintained Data Dictionary captures definitions, ownership, and system of record.

32
MCQmedium

A multinational financial services company uses Salesforce to manage customer interactions. Its data governance team must ensure that all data elements containing Personally Identifiable Information (PII) are consistently classified, protected, and auditable across Production and Full Sandbox environments. The team is considering using Salesforce Data Mask to anonymize PII in Full Sandboxes. However, they are concerned that masking might alter the original data in Production. What is the most accurate statement regarding Data Mask and its role in this governance strategy?

A.Data Mask permanently alters Production data when a masking policy is applied, so it should only be used in Full Sandboxes after a full backup.
B.Data Mask requires the use of Salesforce Shield and can only be applied to custom objects, not standard objects like Account or Contact.
C.Data Mask can be used to mask data in Full Sandboxes, and it does not affect Production data because masking occurs only during sandbox creation or refresh.
D.Data Mask is a real-time field-level encryption service that automatically masks PII in both Production and Sandboxes, eliminating the need for separate policies.
AnswerC

Data Mask is designed to obfuscate data in sandboxes, not Production. Masking policies are applied when a sandbox is created or refreshed, ensuring that sensitive data is replaced before users access the sandbox. This preserves Production data integrity while enabling compliance with data privacy regulations. It is a key governance control for non-production environments.

Why this answer

Data Mask is specifically designed to obfuscate sensitive data in sandboxes without affecting Production. It applies masking policies during sandbox creation or refresh, ensuring that PII is protected in non-production environments while maintaining data integrity in Production. This supports governance by enabling safe testing and development with realistic but anonymized data.

Exam trap

The trap here is assuming that Data Mask modifies Production data or requires Shield, when it actually operates only on sandboxes and can be used independently.

33
MCQeasy

A retail company is implementing a data governance program and needs to define ownership and accountability for data quality. The company has multiple business units, each using Salesforce differently. The governance team wants to ensure that each data domain (e.g., Customer, Product, Order) has a clear owner responsible for data quality, definitions, and issue resolution. Which role should be assigned to fulfill this responsibility?

A.Data Steward
B.Salesforce Administrator
C.Chief Data Officer
D.Data Governance Council
AnswerA

A Data Steward is responsible for day-to-day data quality, including defining data standards, monitoring quality, and resolving issues within a specific domain. They act as the primary point of accountability for data within their domain, ensuring that data meets governance policies. This role is ideal for the described responsibilities.

Why this answer

A Data Steward is the role specifically designed to own data domains, ensure data quality, define standards, and resolve issues. They bridge business and technical teams, providing accountability for data within their domain. This aligns with the governance team's need for clear ownership and accountability at the domain level.

Exam trap

The trap here is confusing strategic roles like the Chief Data Officer or governance bodies with operational domain ownership, which is the Data Steward's responsibility.

34
Multi-Selecthard

A firm is implementing a data stewardship program. Which TWO activities are primary responsibilities of a Data Steward? (Choose Two)

Select 2 answers
A.Define the overarching corporate data strategy.
B.Identify and document data quality issues.
C.Manage metadata and business glossary entries.
D.Design the technical Salesforce architecture.
E.Approve all system-level security access.
AnswersB, C

Data stewards actively monitor data sets to identify inconsistencies, duplicates, or missing information. By logging and documenting these issues, they provide the necessary insight for IT to refine validation rules or automation processes. This proactive documentation is essential for maintaining high trust in the organization's data assets.

Why this answer

Data stewards bridge the gap between technical IT teams and business users. They are responsible for the daily management, quality, and definition of data assets. By ensuring metadata is documented and data quality issues are remediated, they maintain the integrity of the data assets, which is critical for trustworthy analytics and regulatory reporting within the Salesforce ecosystem.

Exam trap

Test-takers often confuse the tactical operational duties of Data Stewards, such as managing metadata and documenting quality issues, with the high-level budget approvals handled by the governance council.

35
MCQmedium

A global organization requires that sensitive customer data be categorized, protected, and auditable across Salesforce Orgs. Which data governance framework component is most effective for ensuring consistent data classification policies?

A.Enable Shield Platform Encryption for all fields.
B.Implement Field Level Security on all PII fields.
C.Define a formal Data Classification Policy.
D.Automate data purging using Apex triggers.
AnswerC

A formal classification policy establishes the metadata tagging and handling rules necessary for governance. It provides a source of truth for technical teams to configure security features accurately. Without this framework, organizations face inconsistent security postures and difficulty proving compliance during audits, as there is no standardized data categorization schema.

Why this answer

Establishing a formal Data Classification Policy is the foundational step for governance. It defines the sensitivity levels and handling requirements for data elements. By standardizing these definitions, architects ensure that technical controls like Shield Platform Encryption or Field Level Security are applied consistently across distributed environments, minimizing risk of unauthorized access and ensuring compliance with global data privacy regulations.

Exam trap

Candidates frequently select technical solutions like Shield Encryption or FLS implementation steps, forgetting that governance frameworks require establishing the overarching policy definitions first.

36
MCQhard

A financial services company must retain Salesforce records for seven years to satisfy a regulator. Records older than two years are rarely accessed but must remain retrievable within 48 hours if requested. The org's data volume is growing 40 percent per year, and the architect wants to minimize storage cost while preserving the ability to restore records with their original Salesforce IDs and relationships. Which approach best meets these requirements?

A.Increase the org's data storage allocation by purchasing additional storage blocks and keep all records online indefinitely.
B.Enable Data Storage Management by deleting records older than two years and relying on Salesforce Recycle Bin for recovery.
C.Use Salesforce Big Objects to archive records and query them with Async SOQL when a regulatory request arrives.
D.Export older records to a CSV file stored in an on-premises file share and delete them from Salesforce.
AnswerC

Big Objects store massive volumes on the Salesforce platform at lower cost and preserve a stable record identifier, so archived records stay queryable without external tooling. Async SOQL retrieves them in bulk for a 48-hour response window. Because the archive remains inside Salesforce, relationships and IDs can be maintained, making this the option that satisfies retention, retrievability, and cost goals together.

Why this answer

Archiving to Big Objects keeps data on-platform, preserves identifiers and relationships, and costs far less than keeping everything in standard storage. Async SOQL supports bulk retrieval so records can be produced within the 48-hour window. Deleting records, exporting to CSV, or simply buying more storage each fail at least one of the three requirements: retention, retrievability, or cost.

Exam trap

The trap here is treating deletion plus Recycle Bin or a CSV export as archiving, when regulatory retention requires durable, queryable storage that preserves IDs and relationships.

37
MCQmedium

A financial services firm is implementing Salesforce and must ensure PII data is managed according to strict regional privacy regulations. Which data governance framework component is most essential for tracking data lifecycle stages from collection to deletion?

A.Implementation of Einstein Data Insights for automated trend analysis.
B.Data Stewardship assignment to the IT department only.
C.Establishment of a Data Lifecycle Management policy.
D.Deployment of a Data Warehouse for all Salesforce logs.
AnswerC

Data Lifecycle Management policies define the end-to-end management of data, including creation, archival, and secure deletion. This is the primary mechanism for ensuring compliance with regional privacy laws like GDPR or CCPA, as it provides the explicit rules for how long sensitive PII should be retained in Salesforce.

Why this answer

A comprehensive Data Lifecycle Management (DLM) policy is critical for regulatory compliance. It provides the structured approach necessary to define how data is acquired, stored, processed, and eventually purged. By enforcing these stages, the organization ensures it does not retain PII longer than legally permitted, mitigating risk and satisfying audit requirements.

This governance component is the foundation for operationalizing privacy by design within the Salesforce ecosystem.

Exam trap

Candidates often select 'Encryption' or 'Field Level Security' as the answer, ignoring that these are technical controls that must be governed by a higher-level lifecycle policy.

Ready to test yourself?

Try a timed practice session using only Sf Data Governance questions.