ISC2 CC Security Principles Practice Question
A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?
⚠ Common exam trap
The trap is treating any customer name or address as merely 'internal' or 'confidential business data' and missing that the presence of SSNs elevates the classification to Sensitive PII with regulatory consequences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitive PII
Names, addresses, and Social Security numbers are the textbook definition of Sensitive PII (Personally Identifiable Information) because they can uniquely identify an individual and, in the case of SSNs, enable identity theft. SSNs are considered highly sensitive regulated data under laws such as GLBA and various state breach notification statutes. Therefore the compromised data falls squarely into the Sensitive PII category rather than any business or public classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Public data
Why it's wrong here
Public data is already lawfully accessible to anyone, so its exposure causes no confidentiality harm. It tempts because names and addresses can sometimes be found in directories, but Social Security numbers are restricted identifiers, making the dataset personally identifiable rather than public.
- ✗
Confidential business data
Why it's wrong here
Confidential business data covers internal trade secrets, financials and strategy, not personally identifiable customer records. It is tempting because breach reports often lump all non-public information together, and it would be the right classification for leaked pricing models, source code or merger plans.
- ✗
Internal data
Why it's wrong here
Internal data denotes information meant only for employees, such as policies or org charts, not customer records held under privacy obligations. It tempts because the breached database sits inside the company, yet the classification follows the data subject, and names, addresses and SSNs are personal data.
- ✓
Sensitive PII
Why this is correct
Names and addresses alone are ordinary PII, but pairing them with Social Security numbers creates data that enables identity theft and financial fraud. That combination meets the definition of sensitive PII, so the breach compromised sensitive PII rather than merely personal or public information.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Personally identifiable information
Personally identifiable information (PII) is any data that can be used to identify, contact, or locate a specific individual, either alone or when combined with other information.
Key term
PII
PII stands for Personally Identifiable Information, which is any data that can be used to identify a specific individual.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.