Courseiva
Asset SecuritymediumMultiple SelectObjective-mapped

CISSP Asset Security Practice Question

A multinational corporation is implementing a data classification policy for commercial data. Which TWO labels are commonly used in commercial classification schemes? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Public

Commercial classification often includes 'Public' for non-sensitive data and 'Private' for internal data. 'Top Secret' and 'Unclassified' are government labels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Public

    Why this is correct

    Public is the lowest level of commercial data classification, designated for information that can be freely disclosed to the general public without causing harm to the organization. Examples include marketing materials, press releases, and public product brochures, which require no confidentiality controls but still demand integrity protections to prevent unauthorized modification.

  • Secret

    Why it's wrong here

    Secret is a formalized military and government data classification level, not typically used in standard commercial frameworks. In government contexts, unauthorized disclosure of Secret information is defined as causing "serious damage" to national security, which carries legal and regulatory implications distinct from corporate data protection schemes.

  • Unclassified

    Why it's wrong here

    Unclassified is a government and military classification category for information that does not meet the threshold for national security protection. While it may still require safeguarding under designations like Controlled Unclassified Information (CUI), it is fundamentally a public sector taxonomy rather than a standard commercial classification tier.

  • Private

    Why this is correct

    Private is a standard commercial classification level used to protect sensitive internal data, such as employee records, personal identifiable information (PII), or internal communications. Unauthorized disclosure of this information could violate privacy regulations like GDPR or HIPAA, or cause significant reputational and financial harm to the corporation.

  • Top Secret

    Why it's wrong here

    Top Secret is the highest level of government and military classification, reserved for information whose unauthorized disclosure would cause "exceptionally grave damage" to national security. Commercial entities do not use this designation for corporate assets, as it is strictly governed by federal executive orders and national defense protocols.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.