mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: A cloud security auditor is assessing a company's…
A cloud security auditor is assessing a company's data classification policy for their cloud environment. Which finding would be considered a critical deficiency?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The data classification scheme does not include labels for public, internal, confidential, and restricted.
Without a classification scheme that includes labels such as public, internal, confidential, and restricted, the organization cannot consistently apply appropriate security controls based on data sensitivity. This is a fundamental deficiency that undermines the entire data security program. While the other options indicate gaps in review cycles, retention periods, or training, they are less critical than the absence of a classification scheme itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The data classification policy is reviewed annually.
Why it's wrong here
Annual review is acceptable.
- ✗
The policy does not specify retention periods for each classification.
Why it's wrong here
Retention periods are important but can be addressed separately.
- ✗
Employees receive data classification training once during onboarding.
Why it's wrong here
While ongoing training is better, initial training is a start.
- ✓
The data classification scheme does not include labels for public, internal, confidential, and restricted.
Why this is correct
Classes are essential for mapping controls to data sensitivity.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.