CISSP Asset Security Practice Question
Which type of data is considered sensitive PII and requires enhanced protection?
⚠ Common exam trap
The trap is treating all PII as equally sensitive; the exam expects you to recognize that government identifiers like SSNs are categorically sensitive and demand enhanced protection beyond ordinary PII.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Social Security number
A Social Security number is a government-issued unique identifier that, if exposed, enables identity theft and fraud, so it is classified as sensitive PII requiring enhanced protection under regulations like GLBA, HIPAA, and state privacy laws. Names, email addresses, and phone numbers are PII but generally lower sensitivity, while job titles are typically not considered sensitive PII at all. The SSN is the classic example of high-sensitivity personal data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Name and email address
Why it's wrong here
These elements, while clearly identifying an individual, are generally classified as non-sensitive PII. Their disclosure primarily facilitates direct communication or marketing efforts rather than enabling immediate financial fraud or identity theft on their own. While important to protect, they do not inherently carry the same high risk of severe personal harm as sensitive identifiers.
- ✗
Job title
Why it's wrong here
A job title, by itself, is typically not considered Personally Identifiable Information (PII), let alone sensitive PII. It describes a role or position within an organization and does not uniquely identify a specific individual without additional contextual data. Its disclosure usually carries minimal risk of personal harm or identity compromise.
- ✗
Phone number
Why it's wrong here
While a phone number is a form of PII that can be used to contact or identify an individual, it is generally not categorized as sensitive PII. Its unauthorized disclosure primarily leads to nuisance calls or targeted marketing, rather than directly enabling severe financial fraud or identity theft. Unlike sensitive identifiers, it does not typically serve as a primary key for accessing critical personal accounts.
- ✓
Social Security number
Why this is correct
A Social Security number (SSN) is unequivocally considered sensitive PII due to its direct linkage to an individual's financial, medical, and governmental records. Its compromise presents an extremely high risk of identity theft, financial fraud, and other severe personal harm. Consequently, SSNs require the most stringent security controls and regulatory protections to safeguard individuals from significant adverse impacts.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.