Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company classifies its data into four sensitivity levels: Public, Internal, Confidential, and Restricted. Which type of data would typically be classified as 'Restricted' and require the highest level of security controls?
⚠ Common exam trap
Google Cloud often tests the distinction between Confidential and Restricted data, where candidates mistakenly assume that any sensitive business document (like a product roadmap) qualifies as Restricted, but Restricted is reserved for data with legal or regulatory compliance requirements (e.g., PII, PHI, PCI).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer Social Security Numbers, payment card numbers, and employee health records.
Restricted data, under Google Cloud's data classification framework, includes personally identifiable information (PII) such as Social Security Numbers, payment card numbers (PCI DSS), and protected health information (PHI). These require the highest security controls, including encryption at rest and in transit, strict IAM policies, and Data Loss Prevention (DLP) API scanning to prevent unauthorized access or leakage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Public press releases and marketing materials published on the company website.
Why it's wrong here
Press releases and marketing materials are explicitly intended for public consumption, so they carry no confidentiality obligation. They are classified as Public, the lowest sensitivity tier in most data classification schemes, and require only integrity and availability controls rather than confidentiality controls; encrypting or access-restricting them would add unnecessary friction without improving security.
- ✓
Customer Social Security Numbers, payment card numbers, and employee health records.
Why this is correct
Customer Social Security Numbers are PII regulated under data privacy laws; payment card numbers fall under PCI DSS; employee health records are PHI under HIPAA. These are classified as Restricted because they contain regulated data types that impose mandatory safeguards, breach-notification obligations, and strict access controls; any mishandling creates severe compliance, legal, and reputational risk.
- ✗
Internal meeting notes and project status reports shared among employees.
Why it's wrong here
Meeting notes and project status reports are not intended for external audiences but typically contain operational details without regulated personal or financial data. They map to an Internal classification, which calls for baseline protections like authenticated access and 'internal use only' labeling, but they do not by themselves require encryption-at-rest, privileged access management, or other controls reserved for Restricted data.
- ✗
Product roadmap documents shared only with the product team.
Why it's wrong here
A product roadmap is commercially sensitive, forward-looking strategy, and sharing it only with the product team reflects need-to-know, so it is more sensitive than routine Internal data. It aligns with a Confidential classification where protection focuses on limiting access based on role and preventing leaks to competitors, yet it generally does not contain regulated data elements (PII, PCI, PHI) that would elevate it to Restricted with mandatory compliance controls.
Go deeper
Related to this question
Learn chapter
Data-Driven Decision Making in Business
Key term
Payment Card Industry Data Security Standards
A set of security rules that any company that handles credit card payments must follow to protect cardholder data from theft and fraud.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.