TechKnowSurge
CompTIA Security+ 3.3 CompTIA Security+ 4.2 CompTIA Security+ 5.4
InteractiveSecurityFree

Data Classification Sorter

Sort data items into the four-tier classification model: Public, Internal, Confidential, or Restricted.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The instinct this activity is built to correct is treating classification as a feeling about how secret something sounds. It is not — it is a question about consequence: if this item appeared on the open internet tomorrow morning, what actually happens? Public means the answer is "nothing, we published it on purpose." Internal means "embarrassing and unhelpful, but survivable" — the item is for everyone inside and no one outside. Confidential means real harm to the business or to a named person, so access is granted deliberately rather than by default. Restricted is the tier where the harm is legal or regulatory rather than merely commercial, and the controls tighten accordingly. Run the consequence test on each card and most of the hard ones resolve themselves. The traps here mostly punish the feeling-based instinct. The office Wi-Fi password is the sharpest one: it is a password, and passwords feel maximally secret, but it was handed to every employee in the building — anything distributed to the whole staff cannot be Confidential, because Confidential means access is controlled and this has none. It is Internal, and if that sits badly, the right response is not to reclassify it upward but to notice that a shared standing password is a weak control, which is a different lesson. The vulnerability report with a working exploit pulls the same way and belongs in Confidential rather than Restricted: it is genuinely dangerous, but the damage is to this company's systems, not a legal or regulatory breach, and that boundary is what separates the top two tiers. Going the other way, the org chart shown at an all-hands feels published because hundreds of people saw it, but everyone in that room was an employee — broad internal circulation is still internal. Compare it to the job posting, which is on the public website and is Public precisely because the company chose to put it there. The two PII cards are meant to be sorted against each other rather than in isolation. A customer name and email list is personal data and belongs in Confidential; Social Security and government ID numbers are personal data too, and they go to Restricted. Both are PII, so "is it PII?" cannot be the deciding question. What separates them is what an attacker can do with it and what the law says about losing it: an email address enables spam and targeted phishing, while an SSN enables identity theft and drags statutory breach-notification duties along with it. Patient records land in Restricted for the same reason — PHI under HIPAA carries a specific legal regime, not just an expectation of discretion. Encryption private keys and root CA certificates are the one Restricted item that is not about a person at all; they are Restricted because compromising them silently invalidates every other control that depends on them. Misclassification costs in both directions, which is why the third objective exists and why over-classifying is not the safe default it appears to be. Under-classify and you have quietly removed the controls the data needed. Over-classify and you impose approval workflows and encryption requirements on a marketing brochure, which teaches employees that the classification scheme is theater and trains them to route around it — and a scheme people work around protects nothing. "When unsure, mark it Restricted" is a real anti-pattern, not caution. One wrinkle to carry into the exam room: this four-tier ladder is a common corporate convention, not a universal standard, and CompTIA Security+ SY0-701 objective 3.3 lists data classifications as sensitive, confidential, public, restricted, private and critical — six labels rather than four, and not arranged as a strict ladder. The reasoning is identical, and the consequence test above still decides every one of them; what changes is the label set. Expect the tier names to differ between an employer's policy and an exam objective, and treat the question "what happens if this gets out?" as the portable part.

What you'll learn

Aligned to

CompTIA Security+
3.3 Compare and contrast concepts and strategies to protect data.
4.2 Explain the security implications of proper hardware, software, and data asset management.
5.4 Summarize elements of effective security compliance.

Key terms

Data Classification
The process of organizing and labeling data based on its sensitivity or confidentiality level to inform access and handling policies.
Sensitive Data
Information that must be protected from unauthorized access due to its private, confidential, or regulated nature, such as customer records or proprietary business plans.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Protected Health Information
PHI
Protected Health Information is individually identifiable health data covered under HIPAA that requires specific administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability.
Data Handling Procedures
The policies and practices governing how data of a given classification level is stored, accessed, transmitted, and disposed of.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Data Governance
The policies, processes, and standards that define how organizational data is managed, protected, and retained throughout its life cycle.
Data Owner
The individual or role accountable for approving access to a specific data set and ensuring the right people have appropriate access.
Need-to-Know
A security principle that limits access to sensitive information only to individuals who require it to perform their job functions, reducing the organizational attack surface.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →