Topic 12 Practice Test 2 covers Data Protection Strategies for CompTIA Security+ SY0-701 and maps to objective 3.3: Compare and contrast concepts and strategies to protect data. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
Which term describes data stored on media such as disks, databases, backups, or removable storage?
- Data at rest
- Intellectual property
- Geolocation restriction
- Confidential classification
Correct Answer: A
Correct Answer
Answer A is correct because Data at rest means data stored on media such as disks, databases, backups, or removable storage. This is the precise fit for the scenario. Confidential classification serves the different purpose of a restrictive classification for information intended only for specifically authorized users or groups.
Incorrect Answers
Answer B is incorrect because Intellectual property refers to creations or proprietary information protected by legal or business rights. The concept is valid, but it does not match this stem. The required function is data stored on media such as disks, databases, backups, or removable storage, which maps to Data at rest.
Answer C is incorrect because Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location. This could be appropriate elsewhere, but the required function is data stored on media such as disks, databases, backups, or removable storage; that makes Data at rest the precise choice.
Answer D is incorrect because Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups. The question is not asking for this function. It is testing data stored on media such as disks, databases, backups, or removable storage, so Data at rest is the stronger fit.
Question 2
To apply controls mandated by laws or sector regulations, which security approach should be selected?
- Intellectual property
- Data tokenization
- Regulated data
- Sensitive classification
Correct Answer: C
Correct Answer
Answer C is correct because Regulated data means information subject to legal or regulatory handling requirements. The deciding point is functional fit: this option covers the stated need, while Sensitive classification addresses a label indicating information requires protection because unauthorized disclosure or modification could cause harm.
Incorrect Answers
Answer A is incorrect because Intellectual property refers to creations or proprietary information protected by legal or business rights. This could be appropriate elsewhere, but the required function is information subject to legal or regulatory handling requirements; that makes Regulated data the precise choice.
Answer B is incorrect because Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The question is not asking for this function. It is testing information subject to legal or regulatory handling requirements, so Regulated data is the stronger fit.
Answer D is incorrect because Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm. The concept is valid, but it does not match this stem. The required function is information subject to legal or regulatory handling requirements, which maps to Regulated data.
Question 3
To prevent unauthorized use or disclosure of valuable creative and technical assets, which security approach should be selected?
- Confidential classification
- Intellectual property
- Trade secret
- Regulated data
Correct Answer: B
Correct Answer
Answer B is correct because Intellectual property means creations or proprietary information protected by legal or business rights. The deciding point is functional fit: this option covers the stated need, while Regulated data addresses information subject to legal or regulatory handling requirements.
Incorrect Answers
Answer A is incorrect because Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups. The question is not asking for this function. It is testing creations or proprietary information protected by legal or business rights, so Intellectual property is the stronger fit.
Answer C is incorrect because Trade secret refers to confidential business information that derives value from not being generally known. The concept is valid, but it does not match this stem. The required function is creations or proprietary information protected by legal or business rights, which maps to Intellectual property. This question specifically tests the requirement represented by Intellectual property.
Answer D is incorrect because Regulated data refers to information subject to legal or regulatory handling requirements. The concept is valid, but it does not match this stem. The required function is creations or proprietary information protected by legal or business rights, which maps to Intellectual property.
Question 4
Two requirements remain open in a data-protection design review: information subject to legal or regulatory handling requirements; data actively being processed in memory or by an application. Which TWO options close those specific gaps? Choose TWO.
- Trade secret
- Data tokenization
- Regulated data
- Data sovereignty
- Data in use
Correct Answers: C, E
Correct Answers
Answer C is correct because Regulated data means information subject to legal or regulatory handling requirements. The fixed-count item needs this function in the answer set. Data tokenization covers substitution of sensitive values with non-sensitive tokens linked through a protected mapping system, a different requirement.
Answer E is correct because Data in use means data actively being processed in memory or by an application. This option satisfies a specific requirement in the stem; Data tokenization serves substitution of sensitive values with non-sensitive tokens linked through a protected mapping system and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Trade secret means confidential business information that derives value from not being generally known. The fixed-count answer set is Data in use, Regulated data; this option does not fill one of those named functions.
Answer B is incorrect because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The required choices are Data in use, Regulated data. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction. The scenario calls for Data in use, Regulated data. Selecting this option would leave one of those required functions uncovered.
Question 5
What is a classification for information approved for unrestricted external disclosure?
- Data in use
- Data sovereignty
- Public classification
- Restricted classification
Correct Answer: C
Correct Answer
Answer C is correct because Public classification means a classification for information approved for unrestricted external disclosure. This is the precise fit for the scenario. Data sovereignty serves the different purpose of the principle that data is subject to laws and governance requirements based on jurisdiction.
Incorrect Answers
Answer A is incorrect because Data in use refers to data actively being processed in memory or by an application. This could be appropriate elsewhere, but the required function is a classification for information approved for unrestricted external disclosure; that makes Public classification the precise choice.
Answer B is incorrect because Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction. The key mismatch is functional: Public classification addresses a classification for information approved for unrestricted external disclosure, the need stated by the question.
Answer D is incorrect because Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations. The question is not asking for this function. It is testing a classification for information approved for unrestricted external disclosure, so Public classification is the stronger fit.
Question 6
Which restrictive classification for information is intended only for specifically authorized users or groups?
- Confidential classification
- Sensitive classification
- Public classification
- Permission restriction
Correct Answer: A
Correct Answer
Answer A is correct because Confidential classification means a restrictive classification for information intended only for specifically authorized users or groups. This matches the requirement as written. Permission restriction can be valid in another context, but it is used for limiting data access according to identity, role, need, and least privilege.
Incorrect Answers
Answer B is incorrect because Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm. The concept is valid, but it does not match this stem. The required function is a restrictive classification for information intended only for specifically authorized users or groups, which maps to Confidential classification.
Answer C is incorrect because Public classification refers to a classification for information approved for unrestricted external disclosure. The key mismatch is functional: Confidential classification addresses a restrictive classification for information intended only for specifically authorized users or groups, the need stated by the question.
Answer D is incorrect because Permission restriction refers to limiting data access according to identity, role, need, and least privilege. That concept can be valid in another scenario, but this question is testing a restrictive classification for information intended only for specifically authorized users or groups; Confidential classification therefore fits the requirement more directly.
Question 7
To store and process data in ways consistent with applicable national or regional rules, which security approach should be selected?
- Geolocation restriction
- Data sovereignty
- Data in use
- Data encryption
Correct Answer: B
Correct Answer
Answer B is correct because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction. The deciding point is functional fit: this option covers the stated need, while Geolocation restriction addresses a control that limits storage, access, or processing according to geographic location.
Incorrect Answers
Answer A is incorrect because Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location. This could be appropriate elsewhere, but the required function is the principle that data is subject to laws and governance requirements based on jurisdiction; that makes Data sovereignty the precise choice.
Answer C is incorrect because Data in use refers to data actively being processed in memory or by an application. The key mismatch is functional: Data sovereignty addresses the principle that data is subject to laws and governance requirements based on jurisdiction, the need stated by the question.
Answer D is incorrect because Data encryption refers to use of cryptography to make information unreadable without authorized key material. The question is not asking for this function. It is testing the principle that data is subject to laws and governance requirements based on jurisdiction, so Data sovereignty is the stronger fit.
Question 8
The control set for a data-protection design review must address both data moving across a network or communication channel and use of one-way digests to validate that data has not been modified. Which TWO choices map directly to those needs? Choose TWO.
- Permission restriction
- Data hashing
- Data in transit
- Public classification
- Data tokenization
Correct Answers: B, C
Correct Answers
Answer B is correct because Data hashing means use of one-way digests to validate that data has not been modified. The fixed-count item needs this function in the answer set. Data tokenization covers substitution of sensitive values with non-sensitive tokens linked through a protected mapping system, a different requirement.
Answer C is correct because Data in transit means data moving across a network or communication channel. One required function is exactly what this option provides. Permission restriction may be useful elsewhere, but it is used for limiting data access according to identity, role, need, and least privilege.
Incorrect Answers
Answer A is incorrect because Permission restriction means limiting data access according to identity, role, need, and least privilege. The question requires exactly 2 selections: Data hashing, Data in transit. This option falls outside that required set. For example, Data in transit is required for data moving across a network or communication channel.
Answer D is incorrect because Public classification means a classification for information approved for unrestricted external disclosure. The scenario calls for Data hashing, Data in transit. Selecting this option would leave one of those required functions uncovered. For example, Data hashing is required for use of one-way digests to validate that data has not been modified.
Answer E is incorrect because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The required choices are Data hashing, Data in transit. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 9
To protect stored information through encryption and access controls, which security approach should be selected?
- Data in transit
- Trade secret
- Data at rest
- Regulated data
Correct Answer: C
Correct Answer
Answer C is correct because Data at rest means data stored on media such as disks, databases, backups, or removable storage. That makes it the best answer here; Data in transit addresses data moving across a network or communication channel, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Data in transit refers to data moving across a network or communication channel. The scenario instead requires data stored on media such as disks, databases, backups, or removable storage, which is why Data at rest is the better answer; this option serves the different function defined above.
Answer B is incorrect because Trade secret refers to confidential business information that derives value from not being generally known. The concept is valid, but it does not match this stem. The required function is data stored on media such as disks, databases, backups, or removable storage, which maps to Data at rest.
Answer D is incorrect because Regulated data refers to information subject to legal or regulatory handling requirements. The concept is valid, but it does not match this stem. The required function is data stored on media such as disks, databases, backups, or removable storage, which maps to Data at rest.
Question 10
To apply the strongest access and handling restrictions, which security approach should be selected?
- Public classification
- Confidential classification
- Data tokenization
- Restricted classification
Correct Answer: D
Correct Answer
Answer D is correct because Restricted classification means a highly controlled classification for information whose exposure could cause severe harm or violate obligations. This matches the requirement as written. Confidential classification can be valid in another context, but it is used for a restrictive classification for information intended only for specifically authorized users or groups.
Incorrect Answers
Answer A is incorrect because Public classification refers to a classification for information approved for unrestricted external disclosure. The question is not asking for this function. It is testing a highly controlled classification for information whose exposure could cause severe harm or violate obligations, so Restricted classification is the stronger fit.
Answer B is incorrect because Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups. The question is not asking for this function. It is testing a highly controlled classification for information whose exposure could cause severe harm or violate obligations, so Restricted classification is the stronger fit.
Answer C is incorrect because Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. This could be appropriate elsewhere, but the required function is a highly controlled classification for information whose exposure could cause severe harm or violate obligations; that makes Restricted classification the precise choice.
Question 11
Which term describes information subject to legal or regulatory handling requirements?
- Data sovereignty
- Restricted classification
- Regulated data
- Sensitive classification
Correct Answer: C
Correct Answer
Answer C is correct because Regulated data means information subject to legal or regulatory handling requirements. That is the function the question is testing. Sensitive classification would instead be used for a label indicating information requires protection because unauthorized disclosure or modification could cause harm.
Incorrect Answers
Answer A is incorrect because Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction. The key mismatch is functional: Regulated data addresses information subject to legal or regulatory handling requirements, the need stated by the question.
Answer B is incorrect because Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations. This could be appropriate elsewhere, but the required function is information subject to legal or regulatory handling requirements; that makes Regulated data the precise choice.
Answer D is incorrect because Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm. The scenario instead requires information subject to legal or regulatory handling requirements, which is why Regulated data is the better answer; this option serves the different function defined above.
Question 12
Which control limits storage, access, or processing according to geographic location?
- Data at rest
- Permission restriction
- Data encryption
- Geolocation restriction
Correct Answer: D
Correct Answer
Answer D is correct because Geolocation restriction means a control that limits storage, access, or processing according to geographic location. This matches the requirement as written. Data encryption can be valid in another context, but it is used for use of cryptography to make information unreadable without authorized key material.
Incorrect Answers
Answer A is incorrect because Data at rest refers to data stored on media such as disks, databases, backups, or removable storage. The scenario instead requires a control that limits storage, access, or processing according to geographic location, which is why Geolocation restriction is the better answer; this option serves the different function defined above.
Answer B is incorrect because Permission restriction refers to limiting data access according to identity, role, need, and least privilege. This could be appropriate elsewhere, but the required function is a control that limits storage, access, or processing according to geographic location; that makes Geolocation restriction the precise choice.
Answer C is incorrect because Data encryption refers to use of cryptography to make information unreadable without authorized key material. This could be appropriate elsewhere, but the required function is a control that limits storage, access, or processing according to geographic location; that makes Geolocation restriction the precise choice.
Question 13
To avoid unnecessary controls while preserving integrity and availability, which security approach should be selected?
- Trade secret
- Data tokenization
- Geolocation restriction
- Public classification
Correct Answer: D
Correct Answer
Answer D is correct because Public classification means a classification for information approved for unrestricted external disclosure. This matches the requirement as written. Geolocation restriction can be valid in another context, but it is used for a control that limits storage, access, or processing according to geographic location.
Incorrect Answers
Answer A is incorrect because Trade secret refers to confidential business information that derives value from not being generally known. That concept can be valid in another scenario, but this question is testing a classification for information approved for unrestricted external disclosure; Public classification therefore fits the requirement more directly.
Answer B is incorrect because Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. This could be appropriate elsewhere, but the required function is a classification for information approved for unrestricted external disclosure; that makes Public classification the precise choice.
Answer C is incorrect because Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location. The scenario instead requires a classification for information approved for unrestricted external disclosure, which is why Public classification is the better answer; this option serves the different function defined above.
Question 14
To protect information while it is accessible to running processes, which security approach should be selected?
- Data in use
- Data sovereignty
- Sensitive classification
- Regulated data
Correct Answer: A
Correct Answer
Answer A is correct because Data in use means data actively being processed in memory or by an application. That makes it the best answer here; Data sovereignty addresses the principle that data is subject to laws and governance requirements based on jurisdiction, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction. The concept is valid, but it does not match this stem. The required function is data actively being processed in memory or by an application, which maps to Data in use.
Answer C is incorrect because Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm. This could be appropriate elsewhere, but the required function is data actively being processed in memory or by an application; that makes Data in use the precise choice.
Answer D is incorrect because Regulated data refers to information subject to legal or regulatory handling requirements. The scenario instead requires data actively being processed in memory or by an application, which is why Data in use is the better answer; this option serves the different function defined above.
Question 15
The control set for a data-protection design review must address both information subject to legal or regulatory handling requirements and use of one-way digests to validate that data has not been modified. Which TWO choices map directly to those needs? Choose TWO.
- Data tokenization
- Financial information
- Regulated data
- Data hashing
- Public classification
Correct Answers: C, D
Correct Answers
Answer C is correct because Regulated data means information subject to legal or regulatory handling requirements. This option satisfies a specific requirement in the stem; Public classification serves a classification for information approved for unrestricted external disclosure and therefore is not interchangeable with it.
Answer D is correct because Data hashing means use of one-way digests to validate that data has not been modified. The fixed-count item needs this function in the answer set. Financial information covers data relating to payments, accounts, transactions, or financial status, a different requirement.
Incorrect Answers
Answer A is incorrect because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The required choices are Regulated data, Data hashing. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Financial information means data relating to payments, accounts, transactions, or financial status. The fixed-count answer set is Regulated data, Data hashing; this option does not fill one of those named functions. For example, Data hashing is required for use of one-way digests to validate that data has not been modified.
Answer E is incorrect because Public classification means a classification for information approved for unrestricted external disclosure. The fixed-count answer set is Regulated data, Data hashing; this option does not fill one of those named functions. For example, Data hashing is required for use of one-way digests to validate that data has not been modified.
Question 16
Which term describes data moving across a network or communication channel?
- Data encryption
- Data in transit
- Data in use
- Regulated data
Correct Answer: B
Correct Answer
Answer B is correct because Data in transit means data moving across a network or communication channel. That makes it the best answer here; Regulated data addresses information subject to legal or regulatory handling requirements, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Data encryption refers to use of cryptography to make information unreadable without authorized key material. The key mismatch is functional: Data in transit addresses data moving across a network or communication channel, the need stated by the question.
Answer C is incorrect because Data in use refers to data actively being processed in memory or by an application. The question is not asking for this function. It is testing data moving across a network or communication channel, so Data in transit is the stronger fit.
Answer D is incorrect because Regulated data refers to information subject to legal or regulatory handling requirements. The question is not asking for this function. It is testing data moving across a network or communication channel, so Data in transit is the stronger fit.
Question 17
A security plan created during a data-protection design review must provide restrictive classification for information intended only for specifically authorized users or groups, use of cryptography to make information unreadable without authorized key material, and obscuring portions of sensitive data while preserving a usable representation. Which THREE options should be selected? Choose THREE.
- Data tokenization
- Intellectual property
- Data encryption
- Confidential classification
- Data masking
- Data hashing
Correct Answers: C, D, E
Correct Answers
Answer C is correct because Data encryption means use of cryptography to make information unreadable without authorized key material. One required function is exactly what this option provides. Data hashing may be useful elsewhere, but it is used for use of one-way digests to validate that data has not been modified.
Answer D is correct because Confidential classification means a restrictive classification for information intended only for specifically authorized users or groups. This option satisfies a specific requirement in the stem; Intellectual property serves creations or proprietary information protected by legal or business rights and therefore is not interchangeable with it.
Answer E is correct because Data masking means obscuring portions of sensitive data while preserving a usable representation. The fixed-count item needs this function in the answer set. Data hashing covers use of one-way digests to validate that data has not been modified, a different requirement.
Incorrect Answers
Answer A is incorrect because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The scenario calls for Data encryption, Data masking, Confidential classification. Selecting this option would leave one of those required functions uncovered.
Answer B is incorrect because Intellectual property means creations or proprietary information protected by legal or business rights. The question requires exactly 3 selections: Data encryption, Data masking, Confidential classification. This option falls outside that required set. For example, Data encryption is required for use of cryptography to make information unreadable without authorized key material.
Answer F is incorrect because Data hashing means use of one-way digests to validate that data has not been modified. The fixed-count answer set is Data encryption, Data masking, Confidential classification; this option does not fill one of those named functions.
Question 18
An architect working on a data-protection design review needs one capability that provides use of cryptography to make information unreadable without authorized key material and another that provides limiting data access according to identity, role, need, and least privilege. Which TWO selections are the best match? Choose TWO.
- Public classification
- Permission restriction
- Data tokenization
- Data encryption
- Data sovereignty
Correct Answers: B, D
Correct Answers
Answer B is correct because Permission restriction means limiting data access according to identity, role, need, and least privilege. It belongs in the fixed-count answer set because it covers one of the stated requirements. Data sovereignty instead serves the principle that data is subject to laws and governance requirements based on jurisdiction and cannot replace this function.
Answer D is correct because Data encryption means use of cryptography to make information unreadable without authorized key material. One required function is exactly what this option provides. Data tokenization may be useful elsewhere, but it is used for substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.
Incorrect Answers
Answer A is incorrect because Public classification means a classification for information approved for unrestricted external disclosure. The required choices are Data encryption, Permission restriction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. The required choices are Data encryption, Permission restriction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction. The required choices are Data encryption, Permission restriction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 19
The control set for a data-protection design review must address both confidential business information that derives value from not being generally known and highly controlled classification for information whose exposure could cause severe harm or violate obligations. Which TWO choices map directly to those needs? Choose TWO.
- Regulated data
- Restricted classification
- Trade secret
- Intellectual property
- Data at rest
Correct Answers: B, C
Correct Answers
Answer B is correct because Restricted classification means a highly controlled classification for information whose exposure could cause severe harm or violate obligations. This option satisfies a specific requirement in the stem; Regulated data serves information subject to legal or regulatory handling requirements and therefore is not interchangeable with it.
Answer C is correct because Trade secret means confidential business information that derives value from not being generally known. It belongs in the fixed-count answer set because it covers one of the stated requirements. Regulated data instead serves information subject to legal or regulatory handling requirements and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Regulated data means information subject to legal or regulatory handling requirements. The required choices are Trade secret, Restricted classification. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Intellectual property means creations or proprietary information protected by legal or business rights. The required choices are Trade secret, Restricted classification. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Data at rest means data stored on media such as disks, databases, backups, or removable storage. The scenario calls for Trade secret, Restricted classification. Selecting this option would leave one of those required functions uncovered.
Question 20
Which principle data is subject to laws and governance requirements based on jurisdiction?
- Public classification
- Data tokenization
- Data masking
- Data sovereignty
Correct Answer: D
Correct Answer
Answer D is correct because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction. This is the precise fit for the scenario. Public classification serves the different purpose of a classification for information approved for unrestricted external disclosure.
Incorrect Answers
Answer A is incorrect because Public classification refers to a classification for information approved for unrestricted external disclosure. The scenario instead requires the principle that data is subject to laws and governance requirements based on jurisdiction, which is why Data sovereignty is the better answer; this option serves the different function defined above.
Answer B is incorrect because Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system. This could be appropriate elsewhere, but the required function is the principle that data is subject to laws and governance requirements based on jurisdiction; that makes Data sovereignty the precise choice.
Answer C is incorrect because Data masking refers to obscuring portions of sensitive data while preserving a usable representation. This could be appropriate elsewhere, but the required function is the principle that data is subject to laws and governance requirements based on jurisdiction; that makes Data sovereignty the precise choice.