ISC2 CC Security Principles Practice Question
Which of the following is considered sensitive personally identifiable information (PII)?
⚠ Common exam trap
It's easy for candidates to confuse 'PII' with 'sensitive PII' — candidates see common identifiers like DOB or email and assume any personal data qualifies as sensitive, when the exam expects recognition that only categories like medical, financial, or biometric data are sensitive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Medical records
Medical records are classified as sensitive PII because they contain protected health information (PHI) that, if disclosed, can cause significant harm such as discrimination, identity theft, or privacy violations. Regulations like HIPAA and GDPR treat health data as a special category requiring stricter safeguards than ordinary identifiers. Date of birth, telephone number, and email address are direct identifiers but are not inherently sensitive on their own.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Date of birth
Why it's wrong here
A date of birth alone identifies nobody; it becomes PII only when combined with a name or other identifier. The question asks for sensitive PII, which covers data such as health records, biometric data, racial or ethnic origin, or financial account numbers. Date of birth would be the answer if the stem asked for quasi-identifiers.
- ✗
Telephone number
Why it's wrong here
A telephone number is contact PII, not sensitive PII; sensitive categories cover health, biometric, financial and government-identifier data. It is tempting because a number uniquely identifies a subscriber, and it would be correct if the question asked for ordinary PII instead of the sensitive classification.
- ✓
Medical records
Why this is correct
Sensitive PII is data that, if disclosed, could cause harm or enable identity theft. Medical records uniquely combine health information with identifiers, so their exposure triggers legal, privacy and discrimination risks. Names or email addresses alone lack that harm potential, making medical records the sensitive category.
- ✗
Email address
Why it's wrong here
An email address is contact PII, not sensitive PII, which covers data such as health, biometric, financial or government-identifier information. It is tempting because email uniquely identifies a person, and it would be the answer if the question asked for ordinary PII rather than the sensitive category.
Go deeper
Related to this question
Key term
Protected health information
Protected health information (PHI) is any health data that can identify an individual and is subject to strict privacy and security regulations.
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.