CompTIA Security+ (SY0-701)Security ArchitectureHard

An organization's data classification policy defines four levels: Public, Internal, Confidential, and Restricted. A marketing intern accidentally uploads a spreadsheet containing customer Social Security numbers to a folder labeled 'Internal' that is accessible to all employees. Which classification level should this data have been assigned?

  1. AConfidential, because it is used only within one department
  2. BPublic, because it was created by marketing
  3. CInternal, because employees need it for their jobs
  4. DRestricted, because it contains regulated personally identifiable information
Show answer & explanation

Correct answer: D. Restricted, because it contains regulated personally identifiable information

Data containing regulated PII such as Social Security numbers warrants the highest classification tier (Restricted) due to legal, regulatory, and breach-notification obligations, requiring the strictest access controls rather than broad employee access.

Why the other options are wrong

  • A. Confidential typically covers sensitive business data but not necessarily the highest-tier regulated PII.
  • B. Public data is intended for open release and is the opposite of sensitive PII.
  • C. Internal-level access allows all employees to view the file, which is inappropriate for SSNs.

Data Classification Levels

A tiered labeling system (commonly Public, Internal, Confidential, Restricted) used to determine required handling and access controls based on data sensitivity.

  • Higher tiers require stricter access controls and encryption
  • Regulated data (PII, PHI, PCI) typically requires the highest classification
  • Mislabeling data can lead to compliance violations and breaches

Memory trick: 'The more it can hurt if leaked, the higher the label goes.'

More Security Architecture questions