SY0-701 Security Program Management and Oversight Practice Question
A file contains employee Social Security numbers and bank account details. The company uses the labels Public, Internal, Confidential, and Restricted. Which label is most appropriate?
⚠ Common exam trap
A common mix-up: candidates confuse 'Confidential' with 'Restricted', assuming any sensitive data fits the 'Confidential' label, but 'Restricted' is specifically reserved for data that is both highly sensitive and subject to regulatory compliance requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted, because it contains highly sensitive personal and financial information
Social Security numbers and bank account details are classified as personally identifiable information (PII) and financial data, which are subject to strict regulatory requirements (e.g., GDPR, PCI DSS). The 'Restricted' label is designed for the most sensitive data that requires the highest level of access control and encryption, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Public, because employees may need to share it with outside vendors
Why it's wrong here
Public is incorrect because data classification is based on sensitivity and legal requirements, not on who might need access. Sharing employee SSNs and bank details with outside vendors would require a data processing agreement and strict safeguards, but the data itself remains highly restricted and must never be broadly distributed. Public data is intended for unrestricted use, whereas this information could enable identity theft or financial fraud.
- ✗
Internal, because only company staff should see it
Why it's wrong here
Internal is too broad of a classification for this dataset. While it is true that only company staff should access the file, internal data is typically available to all employees within the organization. SSNs and bank account numbers demand least-privilege access and need-to-know restrictions, meaning only specific authorized roles (e.g., payroll or HR) should see them, not the entire workforce, so Internal lacks the granularity required.
- ✗
Confidential, because the information is sensitive but not highly regulated
Why it's wrong here
Confidential is insufficient because it underestimates the regulatory and harm implications. While confidential data is sensitive, it usually refers to proprietary business information that requires moderate protection. This data includes personally identifiable information (PII) and financial records that are heavily regulated by laws like GLBA and GDPR, and unauthorized access could result in severe financial and reputational damage, making Restricted the appropriate level.
- ✓
Restricted, because it contains highly sensitive personal and financial information
Why this is correct
Restricted is correct because this file contains highly sensitive personal data (SSNs) and financial account numbers, which are commonly classified at the highest level of restriction. Such data requires strong access controls, encryption, audit logging, and adherence to privacy regulations, as a breach could lead to identity theft, financial fraud, and legal penalties. Restricted classification ensures only authorized personnel with a legitimate business need can access the data.
Go deeper
Related to this question
Learn chapter
Compliance and Regulatory Frameworks
Key term
PCI DSS
The Payment Card Industry Data Security Standard is a set of security requirements designed to protect credit card data during storage, processing, and transmission.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.