SY0-701 Question 219
Single answerData classifications: Sensitive , Confidential , Public , Restricted , Private , CriticalA healthcare organization is updating its data handling standard after several employees shared files through the wrong channels. The security administrator must choose the correct classification for a spreadsheet that contains patients' names, medical record numbers, diagnosis codes, and treatment details. The organization uses the following labels: Public, Sensitive, Private, Confidential, Restricted, and Critical. Which classification is the MOST appropriate for this spreadsheet?
- A
Public
- B
Sensitive
- C
Private
- D
Restricted
Show answer and explanation
Correct answer: D
Explanation
The best answer is Restricted because the scenario describes protected health information (PHI), including patient identifiers and treatment details. In most classification schemes, data subject to strict legal, regulatory, or contractual protection requirements is placed in the highest or one of the highest classification tiers, often labeled Restricted. Security+ expects candidates to map data sensitivity and business impact to appropriate controls and handling requirements rather than rely on generic definitions alone.
Although classification names vary by organization, common best practice is to classify data based on confidentiality requirements, legal obligations, and business impact if the data is disclosed, altered, or destroyed. Healthcare records typically require strong controls such as least privilege, encryption, audit logging, secure transmission, and limited retention/disclosure. These practices align with regulatory expectations such as the HIPAA Security Rule, which requires covered entities to protect electronic PHI with administrative, physical, and technical safeguards. NIST guidance, such as NIST SP 800-60 and NIST SP 800-122, also supports assigning stronger protections to personally identifiable and regulated data based on impact and sensitivity.
- A. Incorrect.
Public is incorrect because public data is intended for open release and would not cause harm if disclosed. Patient medical information is not meant for unrestricted distribution and is protected by privacy and regulatory requirements.
- B. Incorrect.
Sensitive is incorrect because sensitive data may cause some harm or require careful handling, but this option is too broad and generally used for information with lower impact than regulated health records. In this scenario, the spreadsheet contains highly regulated personal and medical data, so a stronger classification is warranted.
- C. Incorrect.
Private is incorrect because private data often refers to personal information intended for limited internal access, such as employee contact details or nonpublic personal identifiers. While patient information is private in a general sense, the presence of medical records and treatment data raises the protection requirement beyond a basic private label.
- D. Correct.
Restricted is correct because the spreadsheet contains highly sensitive, regulated health information whose unauthorized disclosure could result in legal penalties, privacy violations, and significant organizational impact. Restricted is typically used for data requiring the highest level of access control and handling safeguards, which aligns with protected health information.