200-201 Security Policies and Procedures Practice Question
A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)
⚠ Common exam trap
The trap here is assuming that all sensitive data can be handled the same way, when in fact Restricted data demands the strictest controls, including encryption and need-to-know access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access is limited to a need-to-know basis with strict approval workflows.
Restricted data, as the highest classification, requires strong protections such as encryption at rest and in transit, and access limited to a need-to-know basis with strict approvals. These controls reduce the risk of unauthorized disclosure. Free sharing, mandatory removable media storage, and automatic declassification are not typical requirements and would weaken security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data can be declassified to Public after 30 days automatically.
Why it's wrong here
Automatic declassification after a fixed period is not a standard handling requirement for restricted data. Declassification typically requires a formal review and approval process based on the data's sensitivity and business need. Automatic declassification could lead to unintended exposure of highly sensitive information.
- ✓
Access is limited to a need-to-know basis with strict approval workflows.
Why this is correct
Restricted data is usually subject to strict access controls, where only individuals with a specific need-to-know and proper approvals can access it. This minimizes the risk of insider threats and accidental exposure. Need-to-know access is a hallmark of handling requirements for the most sensitive data classifications.
- ✗
Data must be stored only on removable media for physical security.
Why it's wrong here
Storing restricted data only on removable media is not a typical requirement and can actually increase risk due to loss or theft. Instead, restricted data is usually stored on secured servers with encryption and access controls. Removable media may be prohibited or tightly controlled for such data, not mandated as the sole storage method.
- ✗
Data can be shared freely within the organization without additional controls.
Why it's wrong here
Restricted data is the most sensitive and cannot be shared freely within the organization. Sharing is limited to authorized personnel with a need-to-know, and additional controls such as encryption and access logging are required. Free sharing would violate the principle of least privilege and increase the risk of data leakage.
- ✓
Data must be encrypted both at rest and in transit.
Why this is correct
Restricted data is the most sensitive classification and typically requires encryption both at rest and in transit to protect it from unauthorized access. This ensures that even if the data is intercepted or a storage device is stolen, it remains unreadable. Encryption is a standard handling requirement for the highest classification levels in most data classification policies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.