The CA Hub
All CAF-3 chapters

CAF-3 · Chapter 2

Data Classification MCQs with Answers

15 multiple-choice questions on Data Classification for CAF-3 Data, Systems and Risks. Try each one before revealing the answer and explanation.

Practise this chapter interactively
  1. Question 1

    The CEO of a multinational bank establishes a vision to migrate 80% of their customer data to a secure cloud environment by 2028 to support analytics-driven decision-making. At which level of data governance is this action taking place?

    • A) Tactical Level
    • B) Operational Level
    • C) Strategic Level
    • D) Execution Level
    Show answer & explanation

    Answer: C) Strategic Level

    The strategic level involves top management (like the Board or CEO) setting the vision, goals, and direction for data governance

  2. Question 2

    An IT manager at a retail chain drafts a new password policy requiring all employees to use 12-character passwords and updates the standard operating procedures for data entry. Which level of data governance does this represent?

    • A) Strategic Level
    • B) Tactical Level
    • C) Operational Level
    • D) Compliance Level
    Show answer & explanation

    Answer: B) Tactical Level

    The tactical level is where middle management translates the strategic vision into actionable plans, frameworks, and policies

  3. Question 3

    A junior data analyst runs a daily script to identify and flag any missing customer email addresses in the company's CRM system. This daily quality check is an example of data governance at the:

    • A) Strategic Level
    • B) Tactical Level
    • C) Operational Level
    • D) Executive Level
    Show answer & explanation

    Answer: C) Operational Level

    The operational level involves day-to-day staff (like Data Stewards or IT personnel) executing the plans and performing daily data quality checks

  4. Question 4

    What is the primary overarching goal of implementing a data governance framework in an organization?

    • A) To eliminate the need for IT security teams.
    • B) To ensure data is accurate, secure, and compliant with regulations.
    • C) To restrict all employees from accessing internal data.
    • D) To increase the cost of data storage.
    Show answer & explanation

    Answer: B) To ensure data is accurate, secure, and compliant with regulations.

    Data governance provides the frameworks, policies, and practices needed to ensure data is accurate, secure, and compliant with regulations, transforming it into a trusted asset . --------------------------------------------------------------------------------

  5. Question 5

    A hospital maintains detailed electronic health records (EHR) containing patients' medical histories, diagnoses, and treatment plans. Under which data classification should this information be categorized?

    • A) Public Data
    • B) Internal Data
    • C) Confidential Data
    • D) Restricted Data
    Show answer & explanation

    Answer: D) Restricted Data

    Restricted data represents the highest security level, encompassing highly sensitive information like patient health records or credit card numbers, which carry massive legal and reputational risks if leaked

  6. Question 6

    A pharmaceutical company’s HR department is managing the upcoming month's payroll and employee salary increments. This data is not meant for general employees but would cause financial risk and internal conflict if leaked. How should this data be classified?

    • A) Public Data
    • B) Internal Data
    • C) Confidential Data
    • D) Restricted Data
    Show answer & explanation

    Answer: C) Confidential Data

    Confidential data is restricted to specific departments (like HR or Finance) and carries high financial risk or loss of competitive edge if leaked, such as employee salaries or unreleased financial reports

  7. Question 7

    An e-commerce startup circulates a "New Employee Onboarding Handbook" outlining office timings and dress codes on its internal employee portal. This data carries low risk if accidentally seen by an outsider. It is classified as:

    • A) Public Data
    • B) Internal Data
    • C) Confidential Data
    • D) Restricted Data
    Show answer & explanation

    Answer: B) Internal Data

    Internal data is restricted to employees only but carries low risk if leaked, such as internal memos or employee handbooks

  8. Question 8

    A university publishes its upcoming fall semester course catalog and marketing brochure on its official website. This data is classified as:

    • A) Public Data
    • B) Internal Data
    • C) Open-Source Data
    • D) Confidential Data
    Show answer & explanation

    Answer: A) Public Data

    Public data is safe for anyone to view and carries zero risk if accessed by outsiders, such as marketing brochures or website info . --------------------------------------------------------------------------------

  9. Question 9

    In a telecommunications company, the Chief Marketing Officer (CMO) is ultimately accountable for the customer subscriber database and officially approves who gets access rights to this data. The CMO is acting as the:

    • A) Data Steward
    • B) Data Custodian
    • C) Data Owner
    • D) Data Processor
    Show answer & explanation

    Answer: C) Data Owner

    A Data Owner is a senior executive who is ultimately accountable for the data asset, defines policies, and approves access rights

  10. Question 10

    A retail chain appoints a specialized employee to oversee customer data across its CRM systems on a daily basis. This employee resolves discrepancies, merges duplicate entries, and trains store managers on proper data entry practices. This role is known as a:

    • A) Data Owner
    • B) Data Steward
    • C) Database Administrator
    • D) Strategic Manager
    Show answer & explanation

    Answer: B) Data Steward

    A Data Steward is responsible for the day-to-day management of data, enforcing policies, fixing data errors, and maintaining data quality . --------------------------------------------------------------------------------

  11. Question 11

    A university's database is programmed to reject any student enrollment record where the "Date of Birth" is entered as a date in the future. Which type of data integrity is the database enforcing?

    • A) Physical Integrity
    • B) Entity Integrity
    • C) Referential Integrity
    • D) Logical Integrity
    Show answer & explanation

    Answer: D) Logical Integrity

    Logical integrity ensures that the data makes logical sense and adheres to defined business rules, such as age not being negative or a birth date not being in the future

  12. Question 12

    When attempting to delete a vendor from the company's ERP system, an accountant receives an error message stating: "Cannot delete vendor. Active purchase orders are still linked to this vendor ID." This control enforces:

    • A) Referential Integrity
    • B) Entity Integrity
    • C) Physical Integrity
    • D) Logical Integrity
    Show answer & explanation

    Answer: A) Referential Integrity

    Referential integrity maintains valid relationships between tables using Foreign Keys, ensuring that parent records (like a vendor) cannot be deleted if child records (like pending orders) are still linked to them

  13. Question 13

    To ensure that no two citizens are accidentally merged or confused in the national database, the government assigns a unique 13-digit CNIC number to every individual as a Primary Key. This practice maintains:

    • A) Logical Integrity
    • B) Entity Integrity
    • C) Referential Integrity
    • D) Physical Integrity
    Show answer & explanation

    Answer: B) Entity Integrity

    Entity integrity ensures that every record in a database is unique, typically by using a Primary Key to prevent duplicate entries

  14. Question 14

    A cloud service provider installs temperature sensors, fire suppression systems, and backup generators in its data center to ensure servers remain operational during extreme weather conditions. This protects the database's:

    • A) Referential Integrity
    • B) Entity Integrity
    • C) Logical Integrity
    • D) Physical Integrity
    Show answer & explanation

    Answer: D) Physical Integrity

    Physical integrity involves protecting the physical hardware from power outages, fires, or damage using backups, UPS, and environmental controls . --------------------------------------------------------------------------------

  15. Question 15

    A financial institution stores its highly restricted customer transaction data on its own physical servers to maintain maximum security control, while it hosts its general marketing analytics data on Microsoft Azure to save costs. This approach is an example of:

    • A) Fully On-Premises Storage
    • B) Cloud Storage
    • C) Hybrid Storage
    • D) Edge Computing
    Show answer & explanation

    Answer: C) Hybrid Storage

    Hybrid storage is a combination of on-premises and cloud storage, allowing organizations to keep sensitive data on their own servers while utilizing the cloud for less critical, scalable data

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise →