100-140 · Question #80
Company policy states that all sensitive PH will be removed from company servers after 3 months of inactivity. A user requests verification that their data was removed after this date. You check the…
The correct answer is E. Driver's License Number. Under privacy regulations, a Driver's License Number is classified as sensitive Personally Identifiable Information (PII) subject to data retention and removal policies, unlike common contact details.
Question
Options
- AFull Name
- BPhone Number
- CPhysical Address
- DEmail Address
- EDriver's License Number
How the community answered
(25 responses)- A4% (1)
- C4% (1)
- D12% (3)
- E80% (20)
Why each option
Under privacy regulations, a Driver's License Number is classified as sensitive Personally Identifiable Information (PII) subject to data retention and removal policies, unlike common contact details.
A Full Name alone is generally considered non-sensitive PII because it is publicly available and does not uniquely identify a person with enough specificity to cause significant harm if disclosed.
A Phone Number is standard contact information classified as non-sensitive PII; while it should be protected, it does not carry the same risk level as government-issued identifiers.
A Physical Address is non-sensitive PII used routinely in business communications and public records; it does not rise to the level of sensitive PII under most privacy frameworks.
An Email Address is non-sensitive PII used for everyday contact purposes and is not classified as a sensitive identifier requiring special retention controls.
A Driver's License Number is a government-issued identifier that qualifies as sensitive PII - it uniquely identifies an individual and can be used for identity theft or fraud. Privacy frameworks such as HIPAA, GDPR, and NIST guidelines classify government ID numbers as sensitive PII requiring stricter handling, retention limits, and timely removal, distinguishing them from general contact information.
Concept tested: Sensitive PII classification and data retention policies
Source: https://csrc.nist.gov/publications/detail/sp/800-122/final
Topics
Community Discussion
No community discussion yet for this question.