Courseiva
easyMultiple Select

CISA Practice Question: Which TWO are primary criteria for classifying…

Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse operational attributes (format, age, location) with the foundational drivers of classification (business impact and legal/regulatory requirements), leading them to select options that describe how data is stored rather than why it needs protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business impact if the data is lost or disclosed

Option C is correct because the primary purpose of information asset classification is to determine the harm that loss, disclosure, alteration, or unavailability would cause to the organization, so business impact drives the assigned classification level (e.g., Public, Internal, Confidential, Restricted). Option E is correct because legal and regulatory requirements—such as GDPR, HIPAA, PCI DSS, or SOX—mandate specific handling and protection levels, making compliance obligations a fundamental classification criterion. By contrast, option A (data format) affects storage and tooling choices but not the sensitivity-based classification itself, option B (data age) is not a standard classification driver since old data can still be highly sensitive, and option D (physical storage location) is a deployment or residency consideration rather than a primary classification criterion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The format of the data (structured vs. unstructured)

    Why it's wrong here

    Classification reflects the sensitivity and value of information and the impact of its disclosure, plus legal or regulatory obligations. Data format describes structure, not criticality, so structured and unstructured assets can share the same class. Format matters for handling and storage design, not classification criteria.

  • ✗

    The age of the data

    Why it's wrong here

    Age does not determine an asset's sensitivity, regulatory obligations or business criticality, so it cannot drive classification. It is tempting because retention schedules and review cycles reference data age, and age would be relevant when deciding disposal or archival timing, not classification level.

  • ✓

    Business impact if the data is lost or disclosed

    Why this is correct

    Classification hinges on the harm caused by compromise, so business impact from loss or disclosure determines the sensitivity tier and therefore the controls applied. This criterion directly drives handling requirements, making it a primary basis for categorising assets.

  • ✗

    Physical storage location of the data

    Why it's wrong here

    Classification reflects the sensitivity and value of the information and the impact of unauthorised disclosure. Physical location is a storage and jurisdictional control, not a criticality measure; the same asset keeps its class wherever hosted. Location informs residency and access controls, not classification criteria.

  • ✓

    Legal and regulatory requirements

    Why this is correct

    Legal and regulatory requirements impose mandatory handling rules on specific data types, such as personal or financial records, so they directly determine an asset's classification tier. Compliance obligations override discretionary judgements, making this a primary classification criterion.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.