easyMultiple Select
CISA Practice Question: Which TWO of the following are primary objectives…
Which TWO of the following are primary objectives of information classification? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse the secondary benefits of classification (like improved storage management or network design) with its primary objectives, which are strictly about determining protection requirements and ensuring compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine appropriate access controls and protection requirements.
Information classification is the process of labeling data based on its sensitivity and value, and its primary objectives include determining the appropriate access controls and protection requirements (B) — once data is classified (e.g., public, internal, confidential, secret), the organization can apply matching controls such as encryption, RBAC permissions, and handling procedures. It also ensures compliance with legal and regulatory requirements (D), because frameworks like GDPR, HIPAA, PCI DSS, and ISO/IEC 27001 mandate that data be categorized so that mandated safeguards and retention rules can be applied to each class. The remaining options do not belong: network segmentation (A) is a security architecture technique that may follow from classification but is not a primary objective of it, performance prioritization (C) is a QoS/operations concern unrelated to classification's purpose, and deduplication for storage savings (E) is a data-management/storage optimization activity, not a classification objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Simplify network architecture by segmenting data.
Why it's wrong here
Classification assigns sensitivity labels that drive handling and protection rules; it does not segment networks. Network segmentation is tempting because classification often precedes it, and segmentation is the correct control when isolating traffic between trust zones, but it is a downstream use, not a classification objective.
- ✓
Determine appropriate access controls and protection requirements.
Why this is correct
Classification assigns sensitivity labels that directly drive which access controls and protection mechanisms apply, satisfying the stem's requirement to identify primary objectives. By mapping data sensitivity to handling rules, it ensures controls such as encryption and permissions match the data's value and risk, rather than being applied uniformly.
- ✗
Improve system performance by prioritizing critical data.
Why it's wrong here
Classification assigns sensitivity labels that drive handling, access and protection controls; it does not tune CPU, caching or query scheduling, so performance gains are incidental. Prioritising critical data for throughput is achieved through quality-of-service or storage tiering, where classification labels may feed the policy but are not the objective.
- ✓
Ensure compliance with legal and regulatory requirements.
Why this is correct
Classification maps data to handling rules, so labelling regulated information lets an organisation apply the retention, disclosure and safeguarding controls that statutes and regulators demand. This directly satisfies the stem's compliance objective, since legal obligations attach to specific data categories, and classification is the mechanism that identifies which records fall under them.
- ✗
Reduce storage costs by identifying duplicate data.
Why it's wrong here
Classification determines handling requirements based on sensitivity, not deduplication or storage economy. Cost reduction is tempting because labelling can inform retention and tiering decisions, and deduplication is the correct technique when reclaiming space from redundant copies, but neither is a primary classification objective.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.