easyMultiple Choice
CISSP Practice Question: A company's data classification policy labels…
A company's data classification policy labels information as 'Internal Use Only' and 'Confidential.' An employee emails a 'Confidential' document to an external partner without authorization. Which type of data security objective has been violated?
⚠ Common exam trap
The trap here is that candidates sometimes conflate 'unauthorized disclosure' with 'integrity' because both involve unauthorized action, but CISSP expects you to map disclosure specifically to confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Confidentiality ensures information is not disclosed to unauthorized parties. Emailing a 'Confidential' document to an external partner without authorization is a direct unauthorized disclosure, which is precisely the confidentiality objective being violated. The classification label itself signals the data was meant to be restricted to authorized internal recipients.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is a security service that provides undeniable proof of the origin or delivery of data, preventing a sender from falsely denying having sent a message or a receiver from falsely denying having received it. While vital for accountability and legal enforceability of transactions, data classification policies primarily focus on protecting information from unauthorized disclosure, modification, or destruction, rather than proving the occurrence of specific actions.
- ✓
Confidentiality
Why this is correct
Confidentiality is the principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. Data classification policies directly support confidentiality by categorizing information based on its sensitivity and value, thereby dictating the necessary controls to prevent unauthorized access and disclosure. Labeling information as 'confidential' explicitly aims to restrict its viewing to approved parties, making unauthorized disclosure a direct violation of this principle.
- ✗
Availability
Why it's wrong here
Availability ensures that authorized users have timely and reliable access to information and systems when needed, preventing disruption of service. While critical for business operations, data classification policies are not primarily designed to guarantee access, but rather to impose restrictions and controls based on the data's sensitivity. The core purpose of classifying data is to manage who can access it and under what conditions, which is distinct from ensuring the system itself is operational and accessible.
- ✗
Integrity
Why it's wrong here
Integrity is the security principle that guarantees information is accurate, complete, and protected from unauthorized modification or destruction throughout its lifecycle. Data classification policies, while indirectly contributing to integrity by controlling who can access data, are fundamentally concerned with preventing unauthorized disclosure of information. The primary focus of a classification label is to protect the secrecy of data, not to prevent its alteration or ensure its correctness.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.