CISSP Asset Security Practice Question
A company is implementing a data classification scheme. Which category should be assigned to internal memos about employee benefit plans that are not intended for public disclosure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Private/Internal
Commercial classification schemes typically use 'Private' for internal data that could cause harm if disclosed, such as employee benefit details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Private/Internal
Why this is correct
This classification is appropriate for data intended for internal company use, where unauthorized external disclosure would not cause severe damage but is still undesirable and could impact privacy or competitive advantage. Employee benefit plans are proprietary internal information that should be protected from public view, aligning perfectly with the 'Private/Internal' designation, which signifies information not meant for public consumption but also not carrying the highest level of sensitivity requiring 'Confidential' controls.
- ✗
Confidential/Restricted
Why it's wrong here
Data classified as Confidential or Restricted typically involves information whose unauthorized disclosure would cause significant damage to the organization, such as severe financial loss, legal penalties, or critical reputational harm. While employee benefit plans require protection, their compromise would generally not lead to the catastrophic impact associated with truly confidential data like trade secrets, unreleased financial statements, or critical intellectual property. This category implies a higher level of risk and protection than what is typically warranted for general internal employee information.
- ✗
Public
Why it's wrong here
Public data is specifically designated for unrestricted external release and consumption, meaning there are no confidentiality requirements or access controls beyond general availability. Employee benefit plans contain proprietary and personal information that is not intended for the general public and would violate privacy expectations if released. Classifying such data as Public would be a severe misclassification, leading to unauthorized disclosure, potential privacy breaches, and a loss of competitive advantage regarding compensation and benefits.
- ✗
Sensitive
Why it's wrong here
While 'sensitive' is a descriptive term often used for data like Personally Identifiable Information (PII) or Protected Health Information (PHI), it is not a universally recognized or standard top-level classification category within most formal commercial data classification schemes. Data classification frameworks typically use defined tiers like Public, Internal, Confidential, or Secret, which provide clear, actionable guidelines for handling and protection. Using 'Sensitive' as a primary classification could lead to ambiguity, inconsistent application of security controls, and difficulty in auditing compliance.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.