mediumMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are valid types of…
Which TWO of the following are valid types of data classification labels commonly used in commercial organizations?
⚠ Common exam trap
In the ISC2 CISSP exam, it's important to distinguish between government classification levels (Top Secret, Secret, Confidential, Unclassified) and commercial classification labels (Public, Internal, Confidential, Restricted). Candidates often mistakenly apply government terms like Top Secret or Unclassified to commercial scenarios, but these are not typically used in commercial organizations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidential
Confidential is a valid data classification label in commercial organizations, typically used to protect sensitive business information that could cause harm if disclosed. It is part of common classification schemes such as Public, Internal, Confidential, and Restricted, aligning with ISO/IEC 27001 guidelines for information asset management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Top Secret
Why it's wrong here
"Top Secret" is a highly restrictive classification primarily used within government and military contexts to protect information that, if disclosed, could cause exceptionally grave damage to national security. While it represents a valid classification level within those specific sectors, it is not a standard or typical data classification type employed in commercial or general business environments, which usually adopt more generalized categories like Confidential, Private, or Public based on business impact.
- ✓
Confidential
Why this is correct
"Confidential" is a widely recognized and valid data classification type, commonly applied to sensitive business information whose unauthorized disclosure could cause significant harm or financial loss to an organization. This classification level typically requires strict access controls, encryption, and other protective measures to ensure its integrity and privacy, making it a cornerstone of commercial data protection policies.
- ✗
Unclassified
Why it's wrong here
"Unclassified" is a specific designation predominantly used within government and military frameworks to indicate information that does not require protection in the interest of national security. While it signifies a lack of sensitivity within those systems, it is not a standard or commonly adopted data classification type in commercial enterprises, which typically use terms like "Public" or "Open" for non-sensitive data.
- ✓
Public
Why this is correct
"Public" is a fundamental and valid data classification type, designating information that is intentionally made available to the general public without restriction and whose disclosure would cause no harm to the organization. This classification is often applied to marketing materials, press releases, or general website content, requiring minimal security controls as its confidentiality is not a concern.
- ✗
For Official Use Only
Why it's wrong here
"For Official Use Only" (FOUO) is a control marking, not a formal classification level, primarily employed by U.S. government agencies to protect unclassified information that is exempt from mandatory public disclosure under the Freedom of Information Act (FOIA). Its specific administrative and legal context makes it an unsuitable and non-standard data classification type for general commercial or private sector use.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.