Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

⚠ Common exam trap

Test-takers frequently confuse 'Confidential' with 'Restricted' — candidates often assume Confidential is the top tier, but in most four-tier schemes Restricted is the highest sensitivity level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restricted

In a four-tier classification scheme (Public, Internal, Confidential, Restricted), Restricted represents the most sensitive data — typically trade secrets, PII under regulation, or data whose breach causes severe legal/financial harm. It therefore requires the highest level of protection, including strict access controls, encryption, and audit logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal

    Why it's wrong here

    Internal data carries limited harm if exposed and typically sits below Confidential and Restricted in sensitivity. Restricted denotes the gravest impact, such as regulatory, financial or safety damage, demanding the strongest controls. The option tempts because Internal is non-public, so staff assume protection is needed, but its required safeguards are lighter than those for Restricted.

  • ✓

    Restricted

    Why this is correct

    Restricted data demands the strongest controls because it carries the greatest potential harm if disclosed, satisfying the stem's requirement for the highest protection level. Public, Internal, and Confidential each warrant progressively less stringent safeguards, so Restricted sits at the top of this four-tier classification scheme.

  • ✗

    Public

    Why it's wrong here

    Public data is intentionally released and causes negligible harm through disclosure, so it receives the lightest handling controls. Restricted, not Public, demands the highest protection because compromise triggers severe regulatory, financial or safety consequences. The option tempts because all data warrants some care, but Public classification explicitly assumes no confidentiality requirement.

  • ✗

    Confidential

    Why it's wrong here

    Confidential data requires strong protection, yet Restricted sits above it, covering the gravest impact such as regulatory penalties or safety harm, and therefore attracts the strictest controls. The option tempts because Confidential sounds like the top tier, but the scheme reserves its highest level for Restricted, which demands additional access, monitoring and handling restrictions.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.