200-201 Security Policies and Procedures Practice Question
A security manager is updating the organization's data classification policy. The policy must align with the CyberOps Associate curriculum and ensure that data handling procedures are consistent. The manager proposes that data classified as 'Public' should still be encrypted when stored on internal servers. Which principle should guide the manager's decision?
⚠ Common exam trap
The trap here is equating defense in depth with encrypting everything, which ignores the purpose of data classification and can lead to inefficient use of security resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data should be protected according to its classification level, and 'Public' data does not require encryption at rest.
The guiding principle is that data protection controls should be commensurate with the data's classification. Public data, by definition, is not sensitive and does not require encryption at rest. Encrypting it would add unnecessary overhead without meaningful security benefit. The policy should ensure that higher classifications, such as Confidential, receive stronger protections like encryption, while Public data can be handled with basic integrity controls. This risk-based approach is consistent with the CyberOps Associate curriculum.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All data must be encrypted at rest regardless of classification to ensure defense in depth.
Why it's wrong here
While defense in depth is a good practice, encrypting all data indiscriminately can be impractical and costly. Public data, by definition, is not sensitive and does not require encryption. Over-encrypting can also complicate data sharing and increase management overhead. The policy should be risk-based, applying encryption where it is needed to protect confidentiality, integrity, or availability based on classification.
- ✗
Encryption is only required for data in transit, not for data at rest, for any classification.
Why it's wrong here
Data at rest also requires protection, especially for confidential or internal data. Encryption at rest prevents unauthorized access if physical media is stolen or compromised. The statement that encryption is only for data in transit is incorrect; many regulations and best practices require encryption at rest for sensitive data. The manager's decision should consider both states, but for Public data, at-rest encryption is not necessary.
- ✓
Data should be protected according to its classification level, and 'Public' data does not require encryption at rest.
Why this is correct
Data classification defines the level of protection required. Public data is intended for unrestricted access and does not contain sensitive information, so encryption at rest is not mandated. Applying unnecessary controls increases cost and complexity without adding security value. The principle is to match controls to the classification, ensuring that resources are allocated appropriately and that handling procedures remain consistent with the data's sensitivity.
- ✗
The classification of data should be based on the cost of encryption, not on its sensitivity.
Why it's wrong here
Data classification should be based on the data's sensitivity, value, and regulatory requirements, not on the cost of implementing controls. Cost may influence the choice of controls, but it should not dictate the classification itself. If cost determined classification, critical data might be under-protected. The manager should first classify data according to its impact if compromised, then select appropriate controls.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.