CompTIA Security+ (SY0-701)Security ArchitectureHard
An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. A marketing intern accidentally uploads a spreadsheet containing customer Social Security numbers to a folder labeled 'Internal' that is accessible to all employees. Which classification level should this data have been assigned?
- AConfidential, because it is used only within one department
- BPublic, because it was created by marketing
- CInternal, because employees need it for their jobs
- DRestricted, because it contains regulated personally identifiable information
Show answer & explanationAnswer & explanation
Correct answer: D. Restricted, because it contains regulated personally identifiable information
Data containing regulated PII such as Social Security numbers warrants the highest classification tier (Restricted) due to legal, regulatory, and breach-notification obligations, requiring the strictest access controls rather than broad employee access.
Why the other options are wrong
- A. Confidential typically covers sensitive business data but not necessarily the highest-tier regulated PII.
- B. Public data is intended for open release and is the opposite of sensitive PII.
- C. Internal-level access allows all employees to view the file, which is inappropriate for SSNs.
Data Classification Levels
A tiered labeling system (commonly Public, Internal, Confidential, Restricted) used to determine required handling and access controls based on data sensitivity.
- Higher tiers require stricter access controls and encryption
- Regulated data (PII, PHI, PCI) typically requires the highest classification
- Mislabeling data can lead to compliance violations and breaches
Memory trick: 'The more it can hurt if leaked, the higher the label goes.'