Courseiva
Data Migration →mediumMultiple Select

SF-Data-Arch Data Migration Practice Question

Which TWO steps are critical when preparing to migrate sensitive PII (Personally Identifiable Information) into Salesforce?

⚠ Common exam trap

Test-takers often focus solely on migration speed and technical mapping, forgetting compliance requirements like PII masking in non-production environments and proper field-level security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform data masking on source datasets for sandboxes.

When migrating PII, Data Architects must prioritize compliance and data protection. Data masking ensures that non-production environments do not contain real sensitive data, while Field-Level Security (FLS) ensures that only authorized users can access the data within production. These steps are essential to maintaining regulatory compliance, such as GDPR or HIPAA, throughout the lifecycle of the data migration project.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perform data masking on source datasets for sandboxes.

    Why this is correct

    Data masking is a mandatory security practice for non-production environments to prevent the exposure of PII. By sanitizing the data before it reaches the sandbox, the risk of data leakage is minimized while still allowing developers to test against realistic, but safe, dataset structures.

  • ✗

    Use the Bulk API for all PII data transfers.

    Why it's wrong here

    While Bulk API is efficient, the API selection is an architectural decision based on volume, not a security requirement for PII. Sensitive data can be migrated using any API; the security controls are enforced by the platform configuration, not the specific transfer protocol chosen.

  • ✓

    Enable Field-Level Security to restrict access to sensitive fields.

    Why this is correct

    Field-Level Security is a foundational platform control that restricts visibility of PII to only those users who require access for their roles. This adheres to the principle of least privilege, ensuring that even if data is successfully migrated, it remains secure from unauthorized internal viewing.

  • ✗

    Delete all audit logs after the migration is complete.

    Why it's wrong here

    Deleting audit logs is a poor security practice and may violate compliance requirements for data traceability. Organizations must retain audit logs to track who accessed or modified data. Proper governance dictates archival, not destruction, of these logs as part of the standard data management lifecycle.

  • ✗

    Export all PII to unencrypted CSV files for mapping.

    Why it's wrong here

    Exporting PII to unencrypted files creates a massive security vulnerability. All data files containing sensitive information must be handled with appropriate encryption at rest and in transit. Standard unencrypted CSVs are a major security risk and are strictly discouraged in professional data architecture practices.

About these practice questions

This SF-Data-Arch question is part of Courseiva's 222-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.