CISSP Asset Security Practice Question
A government contractor handles data classified as 'Secret'. According to government data classification levels, which of the following is the correct order from most restrictive to least restrictive?
⚠ Common exam trap
CISSP often tests the direction of the ordering (most-to-least vs. least-to-most) and the relative position of Confidential, which candidates mistakenly elevate above Secret because the word sounds more sensitive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Top Secret, Secret, Confidential, Unclassified
The U.S. government classification hierarchy, defined by Executive Order 13526, ranks information from most to least restrictive as Top Secret, Secret, Confidential, and Unclassified. Top Secret covers information whose unauthorized disclosure could cause 'exceptionally grave damage' to national security, while Secret and Confidential correspond to 'serious' and 'damage' respectively. Unclassified sits at the bottom with no restriction. Option B is the only choice that lists this order correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confidential, Secret, Top Secret, Unclassified
Why it's wrong here
This sequence is incorrect because it misrepresents the standard government data classification hierarchy. It incorrectly places 'Confidential' as the most sensitive level, followed by 'Secret' and then 'Top Secret', which reverses the true order of sensitivity between these three classifications. The correct descending order of sensitivity should always place 'Top Secret' as the highest, followed by 'Secret', then 'Confidential', and finally 'Unclassified'.
- ✓
Top Secret, Secret, Confidential, Unclassified
Why this is correct
This option correctly lists the U.S. government data classification levels in descending order of sensitivity and potential damage from unauthorized disclosure. 'Top Secret' indicates exceptionally grave damage to national security, 'Secret' indicates serious damage, 'Confidential' indicates damage, and 'Unclassified' indicates no expected damage. This hierarchy is fundamental for implementing appropriate security controls and access restrictions.
- ✗
Unclassified, Confidential, Secret, Top Secret
Why it's wrong here
While this sequence correctly orders the classification levels from least sensitive to most sensitive, the question implicitly or explicitly (based on the provided correct answer) expects the order from most restrictive/sensitive to least restrictive/sensitive. Therefore, presenting them in an ascending order of sensitivity does not align with the standard hierarchical context for listing security classifications, which typically prioritizes the highest level first.
- ✗
Secret, Top Secret, Confidential, Unclassified
Why it's wrong here
This order is incorrect because it improperly places 'Secret' before 'Top Secret' in the hierarchy of sensitivity. In the established government classification system, 'Top Secret' represents a significantly higher level of potential damage to national security from unauthorized disclosure compared to 'Secret'. This inversion fundamentally misrepresents the relative importance and protective requirements of these two critical classification levels.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.