mediumMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are essential…
Which TWO of the following are essential components of a data classification policy? (Select two.)
⚠ Common exam trap
ISC2 often tests the distinction between a data classification policy (which defines levels and roles) and supporting policies (retention, encryption, destruction) that operationalize the classification but are not core components of the classification policy itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roles and responsibilities for data classification
Roles and responsibilities are essential because a data classification policy must clearly define who is accountable for classifying data, who can assign classification levels, and who is responsible for maintaining the labels. Without this, classification efforts become inconsistent and unenforceable, leading to security gaps. The CISSP emphasizes that governance requires clear assignment of ownership and decision-making authority for data assets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data retention periods for each classification level
Why it's wrong here
Data classification policy primarily defines how data is categorized based on its sensitivity and impact. While retention periods are crucial for compliance and data lifecycle management, they dictate how long data must be kept, which is a subsequent control applied after classification, rather than being a core component of the classification scheme itself. The policy focuses on what the data is, not how long it lives.
- ✓
Roles and responsibilities for data classification
Why this is correct
A robust data classification policy must explicitly delineate the roles and responsibilities for its implementation and ongoing management. This includes identifying data owners, data custodians, and users, clarifying who is accountable for initial classification, review, and reclassification, ensuring consistent application and adherence to the policy across the organization. Without clear ownership, the policy cannot be effectively enforced.
- ✓
Definition of classification levels (e.g., public, confidential, secret)
Why this is correct
The foundational element of any data classification policy is the clear and unambiguous definition of its classification levels. These levels, such as Public, Internal Use Only, Confidential, or Secret, must be precisely described, outlining the criteria for assigning data to each level and the potential impact of unauthorized disclosure. This provides the framework for all subsequent data handling and protection decisions.
- ✗
Methods for secure data destruction
Why it's wrong here
Secure data destruction methods, such as degaussing, shredding, or cryptographic erasure, pertain to the secure disposal phase of the data lifecycle. While critical for preventing unauthorized access to discarded data, these methods are operational procedures defined within a data disposal or media sanitization policy, distinct from the initial policy that categorizes data based on its sensitivity. Classification dictates how data should be protected while it exists, not how it ceases to exist.
- ✗
Encryption standards for each classification level
Why it's wrong here
Encryption standards specify the cryptographic algorithms, key lengths, and protocols to be used for protecting data in transit or at rest. These are technical implementation details and specific security controls derived from the classification policy, rather than being a fundamental component of the policy itself. The classification policy establishes what needs protection, while encryption standards define how that protection is technically achieved.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.