easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A data classification scheme includes Public,…
A data classification scheme includes Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?
⚠ Common exam trap
Watch out — candidates often confuse 'Confidential' with the highest level because it sounds more restrictive than 'Restricted', but in this scheme 'Restricted' is explicitly the top tier, requiring the most stringent controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
Restricted is the highest classification level in this scheme, indicating data that would cause severe damage to the organization if disclosed. It requires the strongest access controls, encryption (e.g., AES-256 for data at rest, TLS 1.3 for data in transit), and strict need-to-know policies. This aligns with the principle of protecting data based on its sensitivity and the potential impact of unauthorized disclosure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restricted
Why this is correct
Restricted data represents the highest level of sensitivity within an organization's classification scheme, indicating that unauthorized disclosure would cause severe, potentially catastrophic, damage to the organization, its operations, or its stakeholders. This classification mandates the most stringent security controls, including robust encryption, strict need-to-know access, multi-factor authentication, and continuous monitoring, to ensure maximum protection against compromise. It typically applies to highly confidential intellectual property, top-secret strategic plans, or critical national security information.
- ✗
Internal
Why it's wrong here
Internal data is designated for use exclusively within the organization, intended for employees and authorized contractors, but does not carry the highest level of sensitivity. While its unauthorized disclosure could cause some business inconvenience or minor reputational damage, it typically does not pose a severe risk to the organization's core operations or legal standing. Access controls are necessary to prevent public dissemination, but they are generally less stringent than those applied to confidential or restricted information.
- ✗
Public
Why it's wrong here
Public data is explicitly intended for broad, unrestricted distribution to the general public, meaning its disclosure would cause no harm to the organization. This classification applies to information that is already openly available or is designed to be shared widely, such as marketing materials, press releases, or publicly accessible reports. Consequently, public data requires minimal, if any, confidentiality controls, focusing instead on ensuring availability and integrity for its intended audience.
- ✗
Confidential
Why it's wrong here
Confidential data is highly sensitive information whose unauthorized disclosure would cause significant, but not catastrophic, harm to the organization, potentially leading to financial losses, legal liabilities, or damage to reputation. This classification typically includes proprietary business information, personal identifiable information (PII), or sensitive financial data that requires robust protection beyond internal-only access. While critical, it is generally considered one step below the most extreme 'Restricted' category, which reserves for the absolute highest impact data.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
TLS
Transport Layer Security (TLS) is a cryptographic protocol that encrypts data sent over the internet to keep it private and ensure it hasn’t been tampered with.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.