Courseiva
easyMultiple Select

CISA Practice Question: Which TWO of the following are primary objectives…

Which TWO of the following are primary objectives of information classification? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse the secondary benefits of classification (like improved storage management or network design) with its primary objectives, which are strictly about determining protection requirements and ensuring compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine appropriate access controls and protection requirements.

Information classification is the process of labeling data based on its sensitivity and value, and its primary objectives include determining the appropriate access controls and protection requirements (B) — once data is classified (e.g., public, internal, confidential, secret), the organization can apply matching controls such as encryption, RBAC permissions, and handling procedures. It also ensures compliance with legal and regulatory requirements (D), because frameworks like GDPR, HIPAA, PCI DSS, and ISO/IEC 27001 mandate that data be categorized so that mandated safeguards and retention rules can be applied to each class. The remaining options do not belong: network segmentation (A) is a security architecture technique that may follow from classification but is not a primary objective of it, performance prioritization (C) is a QoS/operations concern unrelated to classification's purpose, and deduplication for storage savings (E) is a data-management/storage optimization activity, not a classification objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Simplify network architecture by segmenting data.

    Why it's wrong here

    Classification assigns sensitivity labels that drive handling and protection rules; it does not segment networks. Network segmentation is tempting because classification often precedes it, and segmentation is the correct control when isolating traffic between trust zones, but it is a downstream use, not a classification objective.

  • ✓

    Determine appropriate access controls and protection requirements.

    Why this is correct

    Classification assigns sensitivity labels that directly drive which access controls and protection mechanisms apply, satisfying the stem's requirement to identify primary objectives. By mapping data sensitivity to handling rules, it ensures controls such as encryption and permissions match the data's value and risk, rather than being applied uniformly.

  • ✗

    Improve system performance by prioritizing critical data.

    Why it's wrong here

    Classification assigns sensitivity labels that drive handling, access and protection controls; it does not tune CPU, caching or query scheduling, so performance gains are incidental. Prioritising critical data for throughput is achieved through quality-of-service or storage tiering, where classification labels may feed the policy but are not the objective.

  • ✓

    Ensure compliance with legal and regulatory requirements.

    Why this is correct

    Classification maps data to handling rules, so labelling regulated information lets an organisation apply the retention, disclosure and safeguarding controls that statutes and regulators demand. This directly satisfies the stem's compliance objective, since legal obligations attach to specific data categories, and classification is the mechanism that identifies which records fall under them.

  • ✗

    Reduce storage costs by identifying duplicate data.

    Why it's wrong here

    Classification determines handling requirements based on sensitivity, not deduplication or storage economy. Cost reduction is tempting because labelling can inform retention and tiering decisions, and deduplication is the correct technique when reclaiming space from redundant copies, but neither is a primary classification objective.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.