CAS-004 Governance, Risk, and Compliance Practice Question
A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?
⚠ Common exam trap
CAS-005 often tests the ordering of classification tiers, tempting candidates to choose 'Confidential' as the highest when 'Restricted' is the top tier in schemes that include both.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
In most data classification schemes, 'Restricted' represents the highest sensitivity level, reserved for data whose unauthorized disclosure would cause severe damage, such as trade secrets, regulated personal data, or national security information. It requires the most stringent controls, including strict access controls, encryption, and auditing. Public, Internal, and Confidential are lower tiers in the typical hierarchy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restricted
Why this is correct
Restricted data demands the strictest controls because it covers information whose exposure causes severe harm, such as trade secrets or regulated personal data. It sits above Confidential, Internal and Public in the classification hierarchy, satisfying the stem's requirement for the highest sensitivity tier needing the most stringent protection.
- ✗
Public
Why it's wrong here
Public data is intentionally released without restriction, so it requires the least stringent controls, not the most. It is tempting because labelling data public genuinely simplifies handling and sharing, which suits marketing material or open datasets where disclosure causes no harm.
- ✗
Internal
Why it's wrong here
Internal data is restricted to employees but causes limited harm on disclosure, so it sits below confidential and restricted tiers. It is tempting because internal classification genuinely justifies access controls and network segmentation, which suits operational documents not intended for external release.
- ✗
Confidential
Why it's wrong here
Confidential sits below the highest tier; schemes typically reserve top stringency for restricted data whose disclosure causes severe harm. It is tempting because confidential genuinely demands encryption and need-to-know access, which suits personal or commercially sensitive records rather than the most damaging categories.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.