hardMultiple Choice
200-201 Practice Question: A company's security policy includes a clause…
A company's security policy includes a clause that all software installed on company devices must be approved by the IT department. An employee installs an unapproved application that later causes a malware infection. Which policy was violated?
⚠ Common exam trap
Cisco often tests the distinction between a proactive policy (AUP) that prevents unauthorized actions and a reactive policy (Incident Response) that handles the aftermath, causing candidates to confuse the policy that was violated with the policy that describes the response to the violation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acceptable Use Policy
The Acceptable Use Policy (AUP) defines what activities and software are permitted on company devices. By installing an unapproved application without IT authorization, the employee violated the AUP, which directly led to the malware infection. This policy is the primary control for preventing unauthorized software installations that bypass security baselines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident Response Policy
Why it's wrong here
Incident Response defines detection, containment and recovery steps once a compromise occurs; it does not approve software. It would apply here only after the malware infection was identified, governing how the security team investigates and remediates the incident.
- ✓
Acceptable Use Policy
Why this is correct
An Acceptable Use Policy governs employee conduct on company systems, explicitly prohibiting installation of unauthorised software. The stem's clause requiring IT approval before installation is a use restriction, not a technical control, so the employee breached the AUP's behavioural mandate rather than any configuration-based safeguard.
- ✗
Data Retention Policy
Why it's wrong here
The clause governs software approval, not retention or disposal of data, so no retention requirement was breached. A Data Retention Policy specifies how long records are kept and when they are destroyed. It is tempting because both are security policies an employee can violate.
- ✗
Remote Access Policy
Why it's wrong here
Remote access governs how external connections into the corporate network are authenticated and controlled, not which applications may be installed locally. It would be the violated policy if the employee had connected in from an unmanaged location without approved VPN or MFA controls.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.