Courseiva
easyMultiple ChoiceObjective-mapped

CISM Practice Question: Refer to the exhibit

Exhibit

Exhibit:
{
  "classification_scheme": {
    "labels": [
      {"id": "P", "name": "Public"},
      {"id": "C", "name": "Confidential"},
      {"id": "R", "name": "Restricted"},
      {"id": "U", "name": "Unclassified"}
    ]
  }
}

Refer to the exhibit. A company implements this data classification scheme. Which risk is most likely introduced by this scheme?

⚠ Common exam trap

The trap here is that candidates often focus on the administrative burden of over-classification (Option A) instead of recognizing that the missing high-sensitivity tier creates a dangerous gap where sensitive data is under-classified and exposed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Under-classification of internal data, leading to exposure

The classification scheme shown in the exhibit (likely a simple three-tier model: Public, Internal, Confidential) fails to include a distinct 'Restricted' or 'Highly Confidential' tier for the most sensitive data. This forces all non-public data into the 'Internal' bucket, which is then handled with the same baseline controls as moderately sensitive information. The primary risk is under-classification of truly sensitive internal data, leading to inadequate access controls and potential exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Over-classification of data, increasing administrative burden

    Why it's wrong here

    Over-classification is possible, but the missing label leads to more under-classification risk.

  • Under-classification of internal data, leading to exposure

    Why this is correct

    Without an 'Internal' label, internal data may be labeled Public, exposing it unintentionally.

  • Inability to audit data access

    Why it's wrong here

    Auditing is possible with the existing labels.

  • Inconsistent handling of confidential data

    Why it's wrong here

    Confidential is well-defined; the issue is with internal data.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.