ISC2 CC Security Principles Practice Question
Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?
⚠ Common exam trap
Candidates often confuse 'Confidential' with 'Restricted'; many candidates assume Confidential is the highest level, but exam frameworks often place Restricted above it for catastrophic harm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
'Restricted' is the highest data classification level in most frameworks, reserved for information whose unauthorized disclosure could cause catastrophic harm to an organization, such as trade secrets, national security data, or highly sensitive personal information. It typically mandates the strictest controls, including encryption, need-to-know access, and often regulatory compliance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confidential
Why it's wrong here
Confidential data causes serious harm if disclosed, but classification schemes reserve the top tier for catastrophic impact, placing Confidential below that level. It is correct when disclosure would cause significant damage yet not threaten the organisation's survival.
- ✗
Public
Why it's wrong here
Public data is approved for unrestricted release, so it carries no catastrophic disclosure impact and needs minimal protection. It is correct when information is already published or intended for open distribution, such as marketing material or public documentation.
- ✗
Internal
Why it's wrong here
Internal covers information whose disclosure causes limited harm, so it sits well below the top classification. It is tempting because most everyday corporate data carries this label, and it would be the right answer if the question asked about routine business documents rather than catastrophic disclosure.
- ✓
Restricted
Why this is correct
Restricted classification applies to information whose disclosure would cause catastrophic harm, demanding the strictest controls. It sits above Confidential, Internal and Public in sensitivity, so it satisfies the stem's requirement for the highest protection level reserved for catastrophic-impact data.
Go deeper
Related to this question
Learn chapter
Security Governance and Compliance
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.