Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A security manager is tasked with classifying…

A security manager is tasked with classifying data based on its sensitivity. Which of the following is the PRIMARY reason for data classification?

⚠ Common exam trap

Test-takers frequently confuse the primary purpose of classification (protection) with secondary outcomes like compliance or access management, leading them to select options B or D instead of the correct risk-based reasoning in A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To ensure appropriate protection measures are applied to data based on its value and sensitivity.

Data classification is the foundational process of assigning a sensitivity label (e.g., Public, Internal, Confidential, Restricted) to information assets. The primary reason is to ensure that appropriate security controls—such as encryption, access control lists (ACLs), and data loss prevention (DLP) policies—are applied proportionally to the data's value and sensitivity, aligning with the principle of defense in depth and risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To ensure appropriate protection measures are applied to data based on its value and sensitivity.

    Why this is correct

    Data classification is the foundational process for assigning a level of sensitivity or criticality to information assets. This categorization directly dictates the specific security controls, such as encryption, access restrictions, and auditing requirements, that must be implemented to safeguard the data throughout its lifecycle. Without proper classification, organizations risk over-protecting low-value data or, more critically, under-protecting highly sensitive information, leading to inefficient resource allocation and increased risk exposure.

  • To satisfy regulatory requirements for data retention.

    Why it's wrong here

    While data classification can indirectly inform retention policies by identifying data types subject to specific regulations, its primary purpose is not to satisfy data retention requirements. Data retention policies dictate how long data must be kept or can be deleted, often driven by legal, regulatory, or operational needs, irrespective of its immediate sensitivity level. Classification focuses on the *protection* level needed *now*, whereas retention focuses on the *lifecycle duration*.

  • To facilitate data sharing across departments without restrictions.

    Why it's wrong here

    Data classification fundamentally aims to control and restrict data sharing based on its sensitivity and the "need-to-know" principle, rather than facilitating unrestricted access. Highly classified data, such as "Confidential" or "Secret," will have stringent sharing protocols, requiring explicit authorization and secure channels, thereby imposing restrictions. The goal is to prevent unauthorized disclosure, not to simplify broad dissemination.

  • To simplify the process of granting access to users.

    Why it's wrong here

    While data classification certainly informs and refines access control mechanisms, its primary objective is not to simplify the process of granting access. Instead, it often makes access granting more complex and granular, requiring stricter validation and justification for higher classifications. The core purpose is to ensure that only authorized individuals with a legitimate need can access specific data, thereby enhancing protection, not merely streamlining administrative tasks.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.