ISC2 CC Security Principles Practice Question
An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)
⚠ Common exam trap
Many exam-takers confuse 'internal use' with 'confidential' — candidates assume anything not published externally is automatically Confidential, but only data whose disclosure causes harm (PII, financials, IP) qualifies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer personally identifiable information (PII)
Option A (customer PII) is correct because personally identifiable information is regulated by laws such as GDPR and CCPA and its exposure can cause identity theft, so it must be classified Confidential or higher. Option C (financial records and projections) is correct because unaudited financials, forecasts, and internal accounting data are material non-public information whose disclosure can harm the organization or violate securities regulations. Option D (trade secrets and intellectual property) is correct because trade secrets derive their value from secrecy, and unauthorized disclosure destroys legal protection and competitive advantage. Option B (public company press releases) is not correct because press releases are intentionally published for public consumption and are therefore Public. Option E (marketing brochures) is not correct because marketing brochures are distributed externally to promote products and contain no sensitive data, making them Public as well.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Customer personally identifiable information (PII)
Why this is correct
Customer PII uniquely identifies individuals and, if disclosed, enables identity theft and triggers breach-notification and privacy-law duties. That harm potential places it at Confidential or higher, satisfying the policy's requirement to protect data whose exposure causes legal, financial or reputational damage to individuals and the organisation.
- ✗
Public company press releases
Why it's wrong here
Press releases are written for external publication, so they carry no confidentiality requirement and belong at Public. It is tempting because corporate communications may seem sensitive, but classification hinges on the impact of unauthorised disclosure, and published material has none.
- ✓
Financial records and projections
Why this is correct
Financial records and projections reveal an organisation's revenue, costs and forecasts, giving competitors and attackers material advantage and creating regulatory exposure. That competitive and legal harm places them at Confidential or higher, satisfying the policy's criterion of protecting data whose unauthorised disclosure damages the organisation or its stakeholders.
- ✓
Trade secrets and intellectual property
Why this is correct
Trade secrets and intellectual property derive their value from exclusivity; disclosure destroys that value permanently and cannot be undone. This satisfies the policy's Confidential-or-higher criterion because unauthorised release causes direct competitive and financial harm, warranting the strictest handling controls.
- ✗
Marketing brochures
Why it's wrong here
Marketing brochures are distributed publicly to promote products, so unauthorised disclosure causes no harm and they sit at Public. It is tempting because marketing material can reference unreleased offerings, but once approved for distribution it is not Confidential.
Go deeper
Related to this question
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.