Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

Which of the following is considered sensitive personally identifiable information (PII)?

⚠ Common exam trap

It's easy for candidates to confuse 'PII' with 'sensitive PII' — candidates see common identifiers like DOB or email and assume any personal data qualifies as sensitive, when the exam expects recognition that only categories like medical, financial, or biometric data are sensitive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Medical records

Medical records are classified as sensitive PII because they contain protected health information (PHI) that, if disclosed, can cause significant harm such as discrimination, identity theft, or privacy violations. Regulations like HIPAA and GDPR treat health data as a special category requiring stricter safeguards than ordinary identifiers. Date of birth, telephone number, and email address are direct identifiers but are not inherently sensitive on their own.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Date of birth

    Why it's wrong here

    A date of birth alone identifies nobody; it becomes PII only when combined with a name or other identifier. The question asks for sensitive PII, which covers data such as health records, biometric data, racial or ethnic origin, or financial account numbers. Date of birth would be the answer if the stem asked for quasi-identifiers.

  • ✗

    Telephone number

    Why it's wrong here

    A telephone number is contact PII, not sensitive PII; sensitive categories cover health, biometric, financial and government-identifier data. It is tempting because a number uniquely identifies a subscriber, and it would be correct if the question asked for ordinary PII instead of the sensitive classification.

  • ✓

    Medical records

    Why this is correct

    Sensitive PII is data that, if disclosed, could cause harm or enable identity theft. Medical records uniquely combine health information with identifiers, so their exposure triggers legal, privacy and discrimination risks. Names or email addresses alone lack that harm potential, making medical records the sensitive category.

  • ✗

    Email address

    Why it's wrong here

    An email address is contact PII, not sensitive PII, which covers data such as health, biometric, financial or government-identifier information. It is tempting because email uniquely identifies a person, and it would be the answer if the question asked for ordinary PII rather than the sensitive category.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.