ISC2 CC Security Principles Practice Question
A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?
⚠ Common exam trap
Test-takers frequently confuse 'Confidential' with 'Restricted' — candidates often assume Confidential is the top tier, but in most four-tier schemes Restricted is the highest sensitivity level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
In a four-tier classification scheme (Public, Internal, Confidential, Restricted), Restricted represents the most sensitive data — typically trade secrets, PII under regulation, or data whose breach causes severe legal/financial harm. It therefore requires the highest level of protection, including strict access controls, encryption, and audit logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internal
Why it's wrong here
Internal data carries limited harm if exposed and typically sits below Confidential and Restricted in sensitivity. Restricted denotes the gravest impact, such as regulatory, financial or safety damage, demanding the strongest controls. The option tempts because Internal is non-public, so staff assume protection is needed, but its required safeguards are lighter than those for Restricted.
- ✓
Restricted
Why this is correct
Restricted data demands the strongest controls because it carries the greatest potential harm if disclosed, satisfying the stem's requirement for the highest protection level. Public, Internal, and Confidential each warrant progressively less stringent safeguards, so Restricted sits at the top of this four-tier classification scheme.
- ✗
Public
Why it's wrong here
Public data is intentionally released and causes negligible harm through disclosure, so it receives the lightest handling controls. Restricted, not Public, demands the highest protection because compromise triggers severe regulatory, financial or safety consequences. The option tempts because all data warrants some care, but Public classification explicitly assumes no confidentiality requirement.
- ✗
Confidential
Why it's wrong here
Confidential data requires strong protection, yet Restricted sits above it, covering the gravest impact such as regulatory penalties or safety harm, and therefore attracts the strictest controls. The option tempts because Confidential sounds like the top tier, but the scheme reserves its highest level for Restricted, which demands additional access, monitoring and handling restrictions.
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.