CISSP Asset Security Practice Question
A multinational corporation is implementing a data classification policy for commercial data. Which TWO labels are commonly used in commercial classification schemes? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Public
Commercial classification often includes 'Public' for non-sensitive data and 'Private' for internal data. 'Top Secret' and 'Unclassified' are government labels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Public
Why this is correct
Public is the lowest level of commercial data classification, designated for information that can be freely disclosed to the general public without causing harm to the organization. Examples include marketing materials, press releases, and public product brochures, which require no confidentiality controls but still demand integrity protections to prevent unauthorized modification.
- ✗
Secret
Why it's wrong here
Secret is a formalized military and government data classification level, not typically used in standard commercial frameworks. In government contexts, unauthorized disclosure of Secret information is defined as causing "serious damage" to national security, which carries legal and regulatory implications distinct from corporate data protection schemes.
- ✗
Unclassified
Why it's wrong here
Unclassified is a government and military classification category for information that does not meet the threshold for national security protection. While it may still require safeguarding under designations like Controlled Unclassified Information (CUI), it is fundamentally a public sector taxonomy rather than a standard commercial classification tier.
- ✓
Private
Why this is correct
Private is a standard commercial classification level used to protect sensitive internal data, such as employee records, personal identifiable information (PII), or internal communications. Unauthorized disclosure of this information could violate privacy regulations like GDPR or HIPAA, or cause significant reputational and financial harm to the corporation.
- ✗
Top Secret
Why it's wrong here
Top Secret is the highest level of government and military classification, reserved for information whose unauthorized disclosure would cause "exceptionally grave damage" to national security. Commercial entities do not use this designation for corporate assets, as it is strictly governed by federal executive orders and national defense protocols.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.