easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A company's data classification policy labels…
A company's data classification policy labels information as 'Internal Use Only' and 'Confidential.' An employee emails a 'Confidential' document to an external partner without authorization. Which type of data security objective has been violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
Confidentiality ensures that data is not disclosed to unauthorized parties. Sending a 'Confidential' document to an external partner without authorization violates confidentiality. Option A (Non-repudiation) is about proof of origin, not disclosure. Option C (Availability) is about ensuring data is accessible when needed. Option D (Integrity) is about accuracy and completeness of data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is a security service that provides undeniable proof of the origin or delivery of data, preventing a sender from falsely denying having sent a message or a receiver from falsely denying having received it. While vital for accountability and legal enforceability of transactions, data classification policies primarily focus on protecting information from unauthorized disclosure, modification, or destruction, rather than proving the occurrence of specific actions.
- ✓
Confidentiality
Why this is correct
Confidentiality is the principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. Data classification policies directly support confidentiality by categorizing information based on its sensitivity and value, thereby dictating the necessary controls to prevent unauthorized access and disclosure. Labeling information as 'confidential' explicitly aims to restrict its viewing to approved parties, making unauthorized disclosure a direct violation of this principle.
- ✗
Availability
Why it's wrong here
Availability ensures that authorized users have timely and reliable access to information and systems when needed, preventing disruption of service. While critical for business operations, data classification policies are not primarily designed to guarantee access, but rather to impose restrictions and controls based on the data's sensitivity. The core purpose of classifying data is to manage who can access it and under what conditions, which is distinct from ensuring the system itself is operational and accessible.
- ✗
Integrity
Why it's wrong here
Integrity is the security principle that guarantees information is accurate, complete, and protected from unauthorized modification or destruction throughout its lifecycle. Data classification policies, while indirectly contributing to integrity by controlling who can access data, are fundamentally concerned with preventing unauthorized disclosure of information. The primary focus of a classification label is to protect the secrecy of data, not to prevent its alteration or ensure its correctness.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.