Courseiva
Asset SecuritymediumMultiple ChoiceObjective-mapped

CISSP Asset Security Practice Question

A company is implementing a data classification scheme. Which category should be assigned to internal memos about employee benefit plans that are not intended for public disclosure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Private/Internal

Commercial classification schemes typically use 'Private' for internal data that could cause harm if disclosed, such as employee benefit details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Private/Internal

    Why this is correct

    This classification is appropriate for data intended for internal company use, where unauthorized external disclosure would not cause severe damage but is still undesirable and could impact privacy or competitive advantage. Employee benefit plans are proprietary internal information that should be protected from public view, aligning perfectly with the 'Private/Internal' designation, which signifies information not meant for public consumption but also not carrying the highest level of sensitivity requiring 'Confidential' controls.

  • Confidential/Restricted

    Why it's wrong here

    Data classified as Confidential or Restricted typically involves information whose unauthorized disclosure would cause significant damage to the organization, such as severe financial loss, legal penalties, or critical reputational harm. While employee benefit plans require protection, their compromise would generally not lead to the catastrophic impact associated with truly confidential data like trade secrets, unreleased financial statements, or critical intellectual property. This category implies a higher level of risk and protection than what is typically warranted for general internal employee information.

  • Public

    Why it's wrong here

    Public data is specifically designated for unrestricted external release and consumption, meaning there are no confidentiality requirements or access controls beyond general availability. Employee benefit plans contain proprietary and personal information that is not intended for the general public and would violate privacy expectations if released. Classifying such data as Public would be a severe misclassification, leading to unauthorized disclosure, potential privacy breaches, and a loss of competitive advantage regarding compensation and benefits.

  • Sensitive

    Why it's wrong here

    While 'sensitive' is a descriptive term often used for data like Personally Identifiable Information (PII) or Protected Health Information (PHI), it is not a universally recognized or standard top-level classification category within most formal commercial data classification schemes. Data classification frameworks typically use defined tiers like Public, Internal, Confidential, or Secret, which provide clear, actionable guidelines for handling and protection. Using 'Sensitive' as a primary classification could lead to ambiguity, inconsistent application of security controls, and difficulty in auditing compliance.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.