100-160 Question 210
Single answerAn organization is planning to classify its data to improve security measures. During a security assessment, you discover that some files contain sensitive customer information, such as credit card numbers and social security numbers. How should this data be classified to ensure proper handling and compliance with regulations?
- A
Public
- B
Sensitive
- C
Confidential
- D
Restricted
Show answer and explanation
Correct answer: D
Explanation
Data containing sensitive customer information, such as credit card numbers and social security numbers, must be classified as 'Restricted' to ensure compliance with regulations and to enforce strict access controls. This classification minimizes the risk of unauthorized access and potential data breaches, which could lead to severe legal and financial consequences.
- A. Incorrect.
Public data is intended for general access and does not require any special handling. Customer information like credit card numbers and social security numbers should not be classified as public.
- B. Incorrect.
Sensitive data is often protected but does not necessarily involve highly critical information like customer financial or personal identifiers. This classification is too lenient for the described data.
- C. Incorrect.
Confidential data may include internal business information or intellectual property, but it does not adequately represent the strict compliance requirements for sensitive customer information.
- D. Correct.
Restricted data is the most secure classification and is used for highly sensitive information, such as customer credit card numbers and social security numbers. This classification ensures compliance with regulations like PCI DSS (Payment Card Industry Data Security Standard) and ensures proper access controls.