SY0-701 exam dumps

SY0-701 practice question 218 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 218

Single answerData classifications: Sensitive , Confidential , Public , Restricted , Private , Critical

A healthcare company is revising its data handling standard after an employee accidentally emailed an internal spreadsheet containing patient names, medical record numbers, and treatment notes to an external vendor. During the review, the security administrator also identifies the following data sets: a public press release, employee home addresses stored in HR files, the CEO's merger plans, and the disaster recovery runbook required to restore critical systems after a ransomware attack. Which data classification should be assigned to the spreadsheet with patient information to ensure the strongest appropriate protections are applied?

  1. A

    Public

  2. B

    Private

  3. C

    Confidential

  4. D

    Restricted

  5. E

    Critical

Show answer and explanation

Correct answer: D

Explanation

The best answer is Restricted because the scenario centers on highly sensitive regulated data whose unauthorized disclosure would cause significant harm to individuals and the organization. In many Security+ style classification models, labels such as Public, Private, Confidential, Restricted, and Critical are used to distinguish different protection needs. Public data is openly shareable. Private data often covers personal information with limited internal access. Confidential data covers sensitive business information. Restricted is reserved for the most sensitive information, especially regulated or high-impact data requiring strict controls. Critical usually reflects operational importance and availability requirements rather than confidentiality level.

In this scenario, the patient spreadsheet contains protected health information, which generally requires strong safeguards under healthcare privacy and security requirements. Best practices from data classification and handling standards emphasize classifying data based on impact from unauthorized disclosure, alteration, or loss, then applying controls such as least privilege, encryption at rest and in transit, DLP, secure disposal, and audit logging. This approach aligns with common guidance from NIST, including FIPS 199 for impact-based categorization and NIST SP 800-60 for mapping information types to security categories, even though organizations may use different internal labels such as Restricted or Confidential.

  • A. Incorrect.

    Public is incorrect. Public data is intended for open distribution and would include materials such as a press release or published marketing content. Patient records are not meant for unrestricted disclosure and exposing them publicly would create legal, regulatory, and privacy violations.

  • B. Incorrect.

    Private is incorrect. Private data typically refers to personal information that should be limited to authorized use, such as employee home addresses or similar personally identifiable information. While patient data does contain private elements, the inclusion of medical record numbers and treatment notes raises the sensitivity well beyond a basic private classification in most organizational schemes.

  • C. Incorrect.

    Confidential is incorrect. Confidential data is generally sensitive business information that should be disclosed only to authorized parties, such as internal financials or merger discussions. Although patient information must be protected, healthcare records commonly require stricter controls than ordinary confidential business data because of regulatory requirements and the high impact of unauthorized disclosure.

  • D. Correct.

    Restricted is correct. Restricted data is typically the highest or one of the highest protection levels in a classification scheme and is used for information that could cause severe harm if disclosed, altered, or destroyed. Patient names, medical record numbers, and treatment notes represent highly sensitive regulated data that should receive the strongest access controls, encryption, transmission restrictions, monitoring, and handling procedures.

  • E. Incorrect.

    Critical is incorrect. Critical refers primarily to the importance of data or systems to business operations and availability, such as a disaster recovery runbook needed to restore systems after an outage or ransomware event. The patient spreadsheet is highly sensitive from a confidentiality perspective, but 'critical' focuses more on operational necessity than on privacy or disclosure impact.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam