easyMultiple ChoiceObjective-mapped
CISM Practice Question: Refer to the exhibit
Exhibit
Exhibit:
{
"classification_scheme": {
"labels": [
{"id": "P", "name": "Public"},
{"id": "C", "name": "Confidential"},
{"id": "R", "name": "Restricted"},
{"id": "U", "name": "Unclassified"}
]
}
}Refer to the exhibit. A company implements this data classification scheme. Which risk is most likely introduced by this scheme?
⚠ Common exam trap
The trap here is that candidates often focus on the administrative burden of over-classification (Option A) instead of recognizing that the missing high-sensitivity tier creates a dangerous gap where sensitive data is under-classified and exposed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Under-classification of internal data, leading to exposure
The classification scheme shown in the exhibit (likely a simple three-tier model: Public, Internal, Confidential) fails to include a distinct 'Restricted' or 'Highly Confidential' tier for the most sensitive data. This forces all non-public data into the 'Internal' bucket, which is then handled with the same baseline controls as moderately sensitive information. The primary risk is under-classification of truly sensitive internal data, leading to inadequate access controls and potential exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Over-classification of data, increasing administrative burden
Why it's wrong here
Over-classification is possible, but the missing label leads to more under-classification risk.
- ✓
Under-classification of internal data, leading to exposure
Why this is correct
Without an 'Internal' label, internal data may be labeled Public, exposing it unintentionally.
- ✗
Inability to audit data access
Why it's wrong here
Auditing is possible with the existing labels.
- ✗
Inconsistent handling of confidential data
Why it's wrong here
Confidential is well-defined; the issue is with internal data.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.