Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A company is implementing a new data classification policy. Sensitive customer data, if compromised, would result in severe financial penalties and reputational damage. According to common security principles, which classification level should this data receive?
- AConfidential
- BInternal
- CPublic
- DRestricted
Show answer & explanationAnswer & explanation
Correct answer: D. Restricted
Data classified as 'Restricted' typically represents the highest level of sensitivity, where unauthorized disclosure would lead to severe consequences, such as legal penalties, significant financial loss, or severe reputational damage. Customer data with high impact fits this category.
Why the other options are wrong
- A. Confidential data is sensitive but usually has a moderate impact if compromised, less severe than 'Restricted'.
- B. Internal data is for internal use only, but its compromise typically has a lower impact than confidential or restricted data.
- C. Public data is intended for general consumption and has minimal impact if compromised.
Data Classification
The process of organizing data into categories based on its sensitivity and impact if compromised, to apply appropriate security controls.
- Helps determine necessary security measures.
- Typically includes categories like Public, Internal, Confidential, Restricted.
- Impact assessment is crucial for classification.
Memory trick: Public parks are open, but Restricted areas are guarded.