Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

⚠ Common exam trap

Candidates often confuse 'Confidential' with 'Restricted'; many candidates assume Confidential is the highest level, but exam frameworks often place Restricted above it for catastrophic harm.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restricted

'Restricted' is the highest data classification level in most frameworks, reserved for information whose unauthorized disclosure could cause catastrophic harm to an organization, such as trade secrets, national security data, or highly sensitive personal information. It typically mandates the strictest controls, including encryption, need-to-know access, and often regulatory compliance requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confidential

    Why it's wrong here

    Confidential data causes serious harm if disclosed, but classification schemes reserve the top tier for catastrophic impact, placing Confidential below that level. It is correct when disclosure would cause significant damage yet not threaten the organisation's survival.

  • ✗

    Public

    Why it's wrong here

    Public data is approved for unrestricted release, so it carries no catastrophic disclosure impact and needs minimal protection. It is correct when information is already published or intended for open distribution, such as marketing material or public documentation.

  • ✗

    Internal

    Why it's wrong here

    Internal covers information whose disclosure causes limited harm, so it sits well below the top classification. It is tempting because most everyday corporate data carries this label, and it would be the right answer if the question asked about routine business documents rather than catastrophic disclosure.

  • ✓

    Restricted

    Why this is correct

    Restricted classification applies to information whose disclosure would cause catastrophic harm, demanding the strictest controls. It sits above Confidential, Internal and Public in sensitivity, so it satisfies the stem's requirement for the highest protection level reserved for catastrophic-impact data.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.