Practice English vocabulary for citizen developer governance: CoE app reviews, security reviews, DLP policies, app inventories, and governance by exception.
0 / 10 completed
1 / 10
What does 'the CoE reviews apps before production' mean?
A low-code CoE establishes standards and provides governance. Pre-production app review catches security issues (exposed sensitive data), performance problems, and policy violations before apps affect live business processes or real customer data.
2 / 10
What does 'the security review checks for data exposure' mean?
Citizen developers may not have security training. Security reviews of low-code apps look for: connectors with overly broad permissions, flows that log sensitive data, apps that expose data to wrong roles, or integrations that move sensitive data outside approved systems.
3 / 10
What does 'the DLP policy prevents sensitive data leaving the organization' mean?
Low-code DLP policies (available in Power Platform, for example) classify connectors as 'business' or 'non-business/blocked' and enforce rules about which connector groups can coexist in a single flow. This prevents data exfiltration via consumer connectors.
4 / 10
What is 'the app inventory that tracks all citizen-developed apps'?
Without an inventory, organizations have 'shadow IT' in their low-code platform — hundreds of undocumented flows and apps accessing sensitive systems. A governed app inventory makes all citizen development visible, enabling risk assessment and lifecycle management.
5 / 10
What is 'governance by exception' in a citizen developer program?
Governance by exception balances agility with control. Most citizen development proceeds without friction (within guardrails). When a maker needs a blocked connector or access to sensitive data, they request an exception — reviewed by the CoE. This avoids blocking innovation while maintaining oversight of high-risk activities.
6 / 10
Sarah (from the Governance team) sent this Slack message to Mark after he submitted a PR for his new 'LeadGen' app: 'Mark, thanks for submitting LeadGen! Just a quick note – we're seeing a lot of apps being built without explicit consideration for data masking. Could you please add some logic to ensure all Personally Identifiable Information (PII) is masked when displayed in the UI?'> Which of the following best describes Sarah's concern?
Sarah is raising a critical governance issue – specifically, Mark's app isn't compliant with established policies regarding PII. The term 'data masking' refers to the technical process of replacing sensitive data with placeholder values. It's common for citizen developers to miss this crucial step, highlighting the need for governance oversight and training.
7 / 10
Review this code review comment: 'The API endpoint /leads doesn't currently validate the incoming data against the schema. This could lead to inconsistent or corrupted data in the database. Consider adding a validation layer.' What does this comment primarily address?
This comment focuses on data governance – specifically, the lack of validation against a defined schema. Schema validation is a core component of ensuring data quality and consistency within an application, aligning with broader governance requirements around data management. Ignoring this can lead to serious problems downstream.
8 / 10
During a standup meeting, David says: 'I'm building an app that automatically generates reports based on sales data. I've added a new field to capture customer feedback directly within the app.' What does David's statement relate to in terms of citizen developer governance?
David's action highlights the critical aspect of regulatory compliance – particularly GDPR. Collecting 'customer feedback' directly within an application necessitates careful consideration of consent mechanisms and data privacy requirements, which are central to governance frameworks. It's not just about automation or KPIs.
9 / 10
Mark is writing the PR description for his 'CustomerOnboarding' app: 'This PR adds a new button to the user interface that allows users to quickly create a support ticket. It integrates with our existing ticketing system via the TicketAPI.' What element of governance is Mark *implicitly* addressing?
Mark is implicitly focusing on system integration governance. When citizen developers build apps that interact with existing systems (like the 'TicketAPI'), it's crucial to ensure these integrations are documented, controlled, and monitored – a core aspect of broader governance policies related to data flows and dependencies.
10 / 10
Emily (a senior developer) is discussing an app with a junior developer: 'Before you deploy this automation workflow, we need to ensure it aligns with our DLP policy. The workflow processes sensitive customer data - we can't allow that data to leave the network without proper controls.' What does Emily mean by 'DLP policy'?
'DLP Policy' stands for Data Loss Prevention. This policy dictates how sensitive information is handled and protected within the organization – specifically, it controls *where* that data can be accessed or transferred to prevent breaches. It's a proactive measure to protect valuable assets.
What will I practise in "Citizen Developer Governance Vocabulary"?
Practice English vocabulary for citizen developer governance: CoE app reviews, security reviews, DLP policies, app inventories, and governance by exception.
How many exercises are in this module?
This module has 10 multiple-choice exercises, each with instant feedback and a full explanation of the correct answer.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
Do I need to create an account to do these exercises?
No account is required. Just click an option to answer — your score for this session is tracked automatically in the progress bar above.
What happens if I choose the wrong answer?
You'll immediately see which answer was correct, plus a full explanation covering the vocabulary and reasoning behind it — mistakes are where most of the learning happens.
Can I retry the exercises if I want a higher score?
Yes — use the "Try again" button on the results screen to reset and go through all the questions again.
Is my progress saved if I close the page?
No. Progress is tracked only for your current visit; reloading or leaving the page resets the counter. This keeps the exercise simple and account-free.
Where can I find more Low-Code & No-Code exercises?
Browse the full Low-Code & No-Code hub for related drills, or check the "Next up" link below to continue with a connected topic.
How is this different from reading an article on the same topic?
Articles explain vocabulary and concepts in prose; this exercise tests and reinforces that vocabulary through active recall with immediate feedback — the two work best together.
Who writes these exercises?
Every exercise is written by the CoderSlingo team, drawing on real workplace English used in IT roles, then reviewed for accuracy and clarity.