Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A data classification scheme includes Public,…

A data classification scheme includes Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

⚠ Common exam trap

Watch out — candidates often confuse 'Confidential' with the highest level because it sounds more restrictive than 'Restricted', but in this scheme 'Restricted' is explicitly the top tier, requiring the most stringent controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Restricted

Restricted is the highest classification level in this scheme, indicating data that would cause severe damage to the organization if disclosed. It requires the strongest access controls, encryption (e.g., AES-256 for data at rest, TLS 1.3 for data in transit), and strict need-to-know policies. This aligns with the principle of protecting data based on its sensitivity and the potential impact of unauthorized disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restricted

    Why this is correct

    Restricted data represents the highest level of sensitivity within an organization's classification scheme, indicating that unauthorized disclosure would cause severe, potentially catastrophic, damage to the organization, its operations, or its stakeholders. This classification mandates the most stringent security controls, including robust encryption, strict need-to-know access, multi-factor authentication, and continuous monitoring, to ensure maximum protection against compromise. It typically applies to highly confidential intellectual property, top-secret strategic plans, or critical national security information.

  • Internal

    Why it's wrong here

    Internal data is designated for use exclusively within the organization, intended for employees and authorized contractors, but does not carry the highest level of sensitivity. While its unauthorized disclosure could cause some business inconvenience or minor reputational damage, it typically does not pose a severe risk to the organization's core operations or legal standing. Access controls are necessary to prevent public dissemination, but they are generally less stringent than those applied to confidential or restricted information.

  • Public

    Why it's wrong here

    Public data is explicitly intended for broad, unrestricted distribution to the general public, meaning its disclosure would cause no harm to the organization. This classification applies to information that is already openly available or is designed to be shared widely, such as marketing materials, press releases, or publicly accessible reports. Consequently, public data requires minimal, if any, confidentiality controls, focusing instead on ensuring availability and integrity for its intended audience.

  • Confidential

    Why it's wrong here

    Confidential data is highly sensitive information whose unauthorized disclosure would cause significant, but not catastrophic, harm to the organization, potentially leading to financial losses, legal liabilities, or damage to reputation. This classification typically includes proprietary business information, personal identifiable information (PII), or sensitive financial data that requires robust protection beyond internal-only access. While critical, it is generally considered one step below the most extreme 'Restricted' category, which reserves for the absolute highest impact data.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.