Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud architect is designing a data classification scheme for a SaaS provider. The provider handles customer data that includes public marketing materials, internal policies, and sensitive customer financial records. Which classification level should be assigned to customer financial records to enforce the highest level of protection?

⚠ Common exam trap

CCSP often tests the tier hierarchy by presenting Confidential as a plausible 'high' answer, trapping candidates who forget that Restricted is the top classification for regulated, severe-impact data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restricted

Customer financial records represent the most sensitive data class in the scenario, requiring the highest protection tier, which is Restricted. Restricted classification enforces strict access controls, encryption, and monitoring appropriate for regulated financial data. Since the question explicitly asks for the highest level of protection, Restricted is the correct mapping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal

    Why it's wrong here

    Internal covers only staff-facing material, granting no elevated protection tier; financial records demand the highest classification. It is tempting because internal policies genuinely warrant restricted distribution, but that tier sits below confidential, so it cannot enforce the strongest controls this scenario requires.

  • ✗

    Public

    Why it's wrong here

    Public classification permits unrestricted disclosure, directly contradicting the requirement for the highest protection on financial records. It is tempting because marketing materials legitimately belong there, but public data carries no access restrictions, so applying it to sensitive records would expose them.

  • ✓

    Restricted

    Why this is correct

    Restricted is the highest classification tier, reserved for data whose disclosure causes severe harm, such as customer financial records. Assigning it satisfies the stem's requirement to enforce the strongest protection, exceeding Confidential or Internal levels used for policies and marketing material.

  • ✗

    Confidential

    Why it's wrong here

    Confidential is a mid-tier label covering internal sensitive data, not the highest protection level; financial records demand the top classification with the strictest controls. Restricted (or equivalent highest tier) is correct. Confidential suits data whose exposure causes moderate harm, such as internal policies.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.