Courseiva
easyMultiple Choice

CISA Practice Question: Is the PRIMARY purpose of a data classification…

Which of the following is the PRIMARY purpose of a data classification scheme?

⚠ Common exam trap

The trap here is that candidates mistake a downstream benefit (like enabling encryption or meeting compliance) for the primary purpose, when the core goal is to drive risk-based security control selection based on data sensitivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To ensure appropriate security controls are applied based on data sensitivity

A data classification scheme assigns sensitivity labels (e.g., public, internal, confidential, restricted) to information assets. Its primary purpose is to ensure that appropriate security controls—such as access control lists, encryption strength, and monitoring—are applied proportionally to the data's sensitivity. Without classification, controls would be either insufficient for high-risk data or overly restrictive for low-risk data, undermining both security and operational efficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To enable encryption of all sensitive data

    Why it's wrong here

    Encryption is a protective control applied according to sensitivity, not the scheme's purpose; classification labels data so controls can be selected proportionately. It is tempting because sensitive data is often encrypted, and classification does drive encryption decisions, but blanket encryption of all sensitive data is a control outcome, not the primary purpose of classifying data.

  • ✗

    To meet regulatory compliance requirements

    Why it's wrong here

    Compliance is a downstream benefit, not the primary purpose. Classification exists to ensure information is handled according to its sensitivity and value, enabling proportionate protection; regulatory mapping follows from that labelling, rather than driving it.

  • ✗

    To define data retention periods

    Why it's wrong here

    Retention periods derive from regulatory and business requirements, not from the classification labels themselves; classification assigns sensitivity levels that then inform handling rules. It is tempting because retention is a common data governance control, and classification does feed retention policies, but retention is a downstream decision rather than the scheme's primary purpose.

  • ✓

    To ensure appropriate security controls are applied based on data sensitivity

    Why this is correct

    Classification assigns sensitivity labels that determine which security controls apply, ensuring protection is proportionate to data value and regulatory requirements. It is the foundational input to control selection, not an end in itself; encryption, access rules and retention all derive from the assigned classification tier.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.