CAS-004 Governance, Risk, and Compliance Practice Question
A multinational corporation is implementing a data classification scheme. Which of the following data types should be classified as 'restricted'?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer PII with legal requirements
Restricted data typically includes information that could cause severe damage if disclosed, such as trade secrets, intellectual property, or personally identifiable information (PII) that is heavily regulated. Public data is for public release. Internal data is for internal use only. Confidential data is sensitive but less critical than restricted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internal meeting minutes
Why it's wrong here
This is internal data, not restricted.
- ✓
Customer PII with legal requirements
Why this is correct
PII with regulatory requirements is often classified as restricted.
- ✗
Employee training materials
Why it's wrong here
This is likely internal data.
- ✗
Marketing brochures
Why it's wrong here
This is typically public data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.