Courseiva
mediumMultiple ChoiceObjective-mapped

CCSP Practice Question: A cloud security auditor is assessing a company's…

A cloud security auditor is assessing a company's data classification policy for their cloud environment. Which finding would be considered a critical deficiency?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The data classification scheme does not include labels for public, internal, confidential, and restricted.

Without a classification scheme that includes labels such as public, internal, confidential, and restricted, the organization cannot consistently apply appropriate security controls based on data sensitivity. This is a fundamental deficiency that undermines the entire data security program. While the other options indicate gaps in review cycles, retention periods, or training, they are less critical than the absence of a classification scheme itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The data classification policy is reviewed annually.

    Why it's wrong here

    Annual review is acceptable.

  • The policy does not specify retention periods for each classification.

    Why it's wrong here

    Retention periods are important but can be addressed separately.

  • Employees receive data classification training once during onboarding.

    Why it's wrong here

    While ongoing training is better, initial training is a start.

  • The data classification scheme does not include labels for public, internal, confidential, and restricted.

    Why this is correct

    Classes are essential for mapping controls to data sensitivity.

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.