hardMultiple Select
CISSP Practice Question: Which TWO of the following are essential…
Which TWO of the following are essential characteristics of an effective information classification scheme?
⚠ Common exam trap
It's easy for candidates to confuse 'essential characteristics of the scheme' with 'supporting activities' (like training) or 'implementation details' (like encryption algorithms), leading them to select options that are good practices but not defining properties of the classification scheme itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Should have clear labels that map to specific handling procedures
Option C is correct because an effective classification scheme must use clear, well-defined labels (e.g., Public, Internal, Confidential, Restricted) that directly map to specific handling procedures such as storage, transmission, and disposal requirements, ensuring users know exactly how to treat each data type. Option E is correct because the scheme must be applied consistently across the entire organization so that the same label means the same thing in every department, avoiding confusion, gaps, and inconsistent protection that could lead to data exposure. Option A is incorrect because the number of classification levels is not fixed at seven; schemes typically use three to five levels, and the right number depends on the organization's needs rather than a minimum count. Option B is incorrect because while training is important for implementation, it is a supporting control rather than an essential characteristic of the classification scheme itself. Option D is incorrect because classification should be based on the data's sensitivity, value, and business impact, not on the encryption algorithm used to protect it, which is a separate technical control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Should have at least seven classification levels to capture granularity
Why it's wrong here
A data classification scheme's effectiveness hinges on its practicality; having an excessive number of classification levels, such as seven or more, often introduces unnecessary complexity. This complexity makes it difficult for users to accurately assign classifications, leading to confusion, inconsistent application across the organization, and ultimately undermining the scheme's primary goal of protecting information based on its sensitivity. Simpler schemes, typically with 3-5 levels, are generally more manageable and effective.
- ✗
Must be accompanied by mandatory training for all users
Why it's wrong here
While mandatory training for all users is absolutely crucial for the successful implementation and ongoing effectiveness of any data classification scheme, it is an operational requirement, not an inherent characteristic of the scheme's design itself. A classification scheme is a set of policies, labels, and procedures; training is the mechanism to educate users on how to apply it. The scheme's characteristics relate to its structure and principles, not the methods used to disseminate knowledge about it.
- ✓
Should have clear labels that map to specific handling procedures
Why this is correct
An essential characteristic of an effective data classification scheme is that its labels (e.g., "Confidential," "Internal Use Only") must directly correspond to specific, actionable handling procedures. These procedures dictate how data at each classification level should be stored, transmitted, accessed, and disposed of. Without this clear mapping, labels become meaningless, as users would lack the necessary guidance to protect information appropriately, rendering the entire classification effort ineffective.
- ✗
Should be based on the encryption algorithm used to protect the data
Why it's wrong here
Data classification fundamentally focuses on the intrinsic sensitivity, value, and criticality of information to the organization, independent of the specific technical controls applied. Basing classification solely on the encryption algorithm used would conflate the data's inherent risk with a particular protection mechanism. While encryption is a vital control for classified data, the classification itself determines *what* needs protection and *why*, not *how* it is protected at a technical level.
- ✓
Must be applied consistently across the entire organization
Why this is correct
For a data classification scheme to be effective and reliable, it must be applied uniformly and consistently throughout the entire organization, regardless of department, location, or data owner. Inconsistent application leads to confusion, creates security gaps, and undermines the organization's overall information security posture. Consistency ensures that all data of similar sensitivity receives the same level of protection and adherence to defined handling procedures, thereby maintaining the integrity of the security framework.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.