nerdexam
CompTIA

SY0-501 · Question #539

An office manager found a folder that included documents with various types of data relating to corporate clients. The office manager notified the data included dates of birth, addresses, and phone…

The correct answer is D. PII. The client data found, including dates of birth, addresses, and phone numbers, constitutes Personally Identifiable Information (PII). The security officer would consult policies related to PII to determine if a breach has occurred.

Submitted by tunde_lagos· Mar 4, 2026Security program management and oversight

Question

An office manager found a folder that included documents with various types of data relating to corporate clients. The office manager notified the data included dates of birth, addresses, and phone numbers for the clients. The office manager then reported this finding to the security compliance officer. Which of the following portions of the policy would the security officer need to consult to determine if a breach has occurred?

Options

  • APublic
  • BPrivate
  • CPHI
  • DPII

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    7% (2)
  • D
    86% (24)

Why each option

The client data found, including dates of birth, addresses, and phone numbers, constitutes Personally Identifiable Information (PII). The security officer would consult policies related to PII to determine if a breach has occurred.

APublic

Public information is generally accessible and does not require specific breach policies when found.

BPrivate

While the data is private, 'Private' is a general descriptor and not the specific classification used in breach policies for this type of sensitive identifying data.

CPHI

Protected Health Information (PHI) specifically refers to health-related data, which was not mentioned as being present in the discovered documents.

DPIICorrect

Personally Identifiable Information (PII) encompasses data points like dates of birth, addresses, and phone numbers that can uniquely identify an individual. Policies are specifically designed to protect PII, and any unauthorized access, disclosure, or loss of such data typically signifies a data breach.

Concept tested: Data classification and breach identification

Source: https://csrc.nist.gov/glossary/term/personally_identifiable_information

Topics

#PII#data classification#privacy#compliance

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice