ISC2 CC Security Principles Practice Question
Which of the following are examples of sensitive PII? (Select all that apply.)
⚠ Common exam trap
CC often tests the distinction between PII and sensitive PII; candidates may incorrectly select phone number or name/email as sensitive, not realizing that sensitivity depends on the potential for harm and regulatory definitions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Medical records
Sensitive PII includes data that, if disclosed, could cause harm or be used for identity theft. Medical records and Social Security numbers are classic examples of sensitive PII because they contain highly confidential information. Phone numbers and name/email address are generally considered PII but not necessarily sensitive PII on their own.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phone number
Why it's wrong here
A phone number identifies an individual but discloses no protected characteristic, so it falls outside sensitive PII categories such as health, financial, biometric or government identifier data. It is tempting because phone numbers are personal data requiring protection, just not the heightened handling sensitive PII demands.
- ✓
Medical records
Why this is correct
Medical records are sensitive PII because they combine an identifier with health data, revealing diagnoses, treatments or conditions. This falls within special-category data under GDPR and triggers stricter handling than ordinary personal data, satisfying the stem's requirement for sensitive rather than generic PII.
- ✓
Social Security number
Why this is correct
A Social Security number uniquely identifies an individual and is issued by a government authority, making it sensitive PII requiring protection under privacy regulations. Its disclosure enables identity theft, distinguishing it from non-identifying data such as product codes or aggregated statistics.
- ✗
Name and email address
Why it's wrong here
A name combined with an email address identifies a specific individual but reveals nothing that could cause harm if exposed, so it is ordinary PII rather than sensitive PII. It is tempting because both fields are personal data, yet sensitive categories cover data such as health, financial or biometric information.
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.