Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidential

Options D and E are correct because data classification policies typically define sensitivity levels that describe who may access the data and how it must be handled. 'Confidential' (D) is a standard classification label for data whose unauthorized disclosure could cause harm, so it is restricted to authorized personnel. 'Public' (E) is the opposite end of the spectrum, labeling data approved for unrestricted release to anyone. These sensitivity tiers are the core of a classification scheme, often alongside labels like Internal or Restricted. The unmarked options do not belong because 'Archived' (A) and 'Backup' (C) describe data lifecycle or storage states, not sensitivity levels, and 'Encrypted' (B) is a protective control applied to data rather than a classification category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Archived

    Why it's wrong here

    Archived describes a data lifecycle or retention state, not a sensitivity tier; classification labels data by impact of disclosure, such as Public, Internal, Confidential or Restricted. It is tempting because archived data often warrants protection, but archiving is a storage decision, so it belongs in retention policy rather than the classification scheme.

  • ✗

    Encrypted

    Why it's wrong here

    Encrypted describes a protective control applied to data, not a classification category; classification assigns sensitivity labels based on impact, independent of whether encryption is used. It is tempting because encryption frequently accompanies higher classifications, but encryption status is a handling requirement derived from the label, not a label itself.

  • ✗

    Backup

    Why it's wrong here

    Backup describes a recovery or availability process, not a sensitivity tier; classification categories reflect the impact of unauthorised disclosure, such as Public, Internal, Confidential and Restricted. It is tempting because backed-up data needs protection, but backup frequency and retention are separate operational policies, not classification labels.

  • ✓

    Confidential

    Why this is correct

    Confidential is a core classification tier, restricting data to authorised personnel only. It sits between internal and secret levels, satisfying the policy's need for a category governing sensitive business or personal information whose disclosure would cause harm.

  • ✓

    Public

    Why this is correct

    Public is a standard classification tier for information approved for unrestricted release. Including it satisfies the policy requirement by defining the lowest sensitivity level, so data with no confidentiality impact is handled and labelled consistently.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.