ISC2 CC Security Principles Practice Question
Which TWO of the following are examples of sensitive PII? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Medical records
Sensitive PII includes medical records and biometrics. Name and email are general PII; IP address is not PII alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Name
Why it's wrong here
A name is standard non-sensitive PII; it identifies an individual but discloses no protected attribute. It is tempting because names are the most obvious personal identifier, and would be correct if the question asked for examples of PII generally rather than sensitive PII categories such as health or financial data.
- ✓
Medical records
Why this is correct
Medical records qualify as sensitive PII because they contain health data, a special category requiring heightened protection under most privacy frameworks. This satisfies the stem's sensitivity constraint, distinguishing them from ordinary identifiers such as names or email addresses, which alone lack the elevated risk profile that triggers stricter handling obligations.
- ✗
Email address
Why it's wrong here
An email address is generally classified as non-sensitive PII; it identifies a person but does not reveal protected characteristics. It is tempting because it is commonly used to contact individuals, and would be the correct answer if the question asked for general PII rather than sensitive PII specifically.
- ✗
IP address
Why it's wrong here
An IP address alone is not sensitive PII; it identifies a device or network connection rather than a specific individual. It is tempting because IP addresses can be logged and correlated to users, and would be treated as personal data under GDPR in some contexts, but it is not a sensitive PII category.
- ✓
Biometric data
Why this is correct
Biometric data uniquely identifies a person through immutable physiological traits, such as fingerprints or facial geometry, and cannot be reissued once compromised. This satisfies the stem's sensitive PII criterion, since exposure enables permanent identity theft and is classified as a special category under GDPR, unlike mutable identifiers such as a phone number.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.