Courseiva
Security Principles →hardMultiple Select

ISC2 CC Security Principles Practice Question

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

⚠ Common exam trap

Many exam-takers confuse 'internal use' with 'confidential' — candidates assume anything not published externally is automatically Confidential, but only data whose disclosure causes harm (PII, financials, IP) qualifies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer personally identifiable information (PII)

Option A (customer PII) is correct because personally identifiable information is regulated by laws such as GDPR and CCPA and its exposure can cause identity theft, so it must be classified Confidential or higher. Option C (financial records and projections) is correct because unaudited financials, forecasts, and internal accounting data are material non-public information whose disclosure can harm the organization or violate securities regulations. Option D (trade secrets and intellectual property) is correct because trade secrets derive their value from secrecy, and unauthorized disclosure destroys legal protection and competitive advantage. Option B (public company press releases) is not correct because press releases are intentionally published for public consumption and are therefore Public. Option E (marketing brochures) is not correct because marketing brochures are distributed externally to promote products and contain no sensitive data, making them Public as well.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Customer personally identifiable information (PII)

    Why this is correct

    Customer PII uniquely identifies individuals and, if disclosed, enables identity theft and triggers breach-notification and privacy-law duties. That harm potential places it at Confidential or higher, satisfying the policy's requirement to protect data whose exposure causes legal, financial or reputational damage to individuals and the organisation.

  • ✗

    Public company press releases

    Why it's wrong here

    Press releases are written for external publication, so they carry no confidentiality requirement and belong at Public. It is tempting because corporate communications may seem sensitive, but classification hinges on the impact of unauthorised disclosure, and published material has none.

  • ✓

    Financial records and projections

    Why this is correct

    Financial records and projections reveal an organisation's revenue, costs and forecasts, giving competitors and attackers material advantage and creating regulatory exposure. That competitive and legal harm places them at Confidential or higher, satisfying the policy's criterion of protecting data whose unauthorised disclosure damages the organisation or its stakeholders.

  • ✓

    Trade secrets and intellectual property

    Why this is correct

    Trade secrets and intellectual property derive their value from exclusivity; disclosure destroys that value permanently and cannot be undone. This satisfies the policy's Confidential-or-higher criterion because unauthorised release causes direct competitive and financial harm, warranting the strictest handling controls.

  • ✗

    Marketing brochures

    Why it's wrong here

    Marketing brochures are distributed publicly to promote products, so unauthorised disclosure causes no harm and they sit at Public. It is tempting because marketing material can reference unreleased offerings, but once approved for distribution it is not Confidential.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.