easyMultiple Choice
200-201 Practice Question: A company's security policy states that employees…
A company's security policy states that employees must not use corporate laptops for personal web browsing. An employee is found to have streamed video during work hours, consuming significant bandwidth. What is the best course of action?
⚠ Common exam trap
200-201 often tests the boundary between technical response and HR/legal process — candidates pick 'terminate' or 'warn' because they sound decisive, but the correct answer is always to follow the documented policy and route through HR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the violation to HR for disciplinary action per the existing policy
When a security policy already exists and an employee is found to have violated it, the correct action is to follow the established disciplinary process — typically reporting the violation to HR so the organisation's policy is enforced consistently. This preserves due process, creates an auditable record, and avoids ad-hoc decisions by the security team. Terminating immediately or ignoring the violation both undermine the policy's authority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Give a verbal warning and take no further action
Why it's wrong here
A verbal warning alone leaves the policy violation unrecorded and unenforced, so the bandwidth misuse and repeat risk persist. Verbal counselling suits trivial first-time breaches; here the documented policy breach and resource impact warrant formal disciplinary steps under the acceptable-use policy.
- ✗
Update the policy to allow streaming under certain conditions
Why it's wrong here
Rewriting the policy to permit streaming legitimises the behaviour instead of addressing the violation, and ignores the bandwidth and acceptable-use controls already in force. Policy revision suits deliberate business change after risk assessment, not as a response to an employee breaching an existing rule.
- ✗
Immediately terminate the employee
Why it's wrong here
Immediate termination disregards the principle of proportionality in security policy enforcement; the violation is a bandwidth-consumption policy breach, not a malicious act that compromised data confidentiality or system integrity. This option is tempting because termination is the correct response for severe infractions such as deliberate data exfiltration or installing unauthorised remote-access tools, where the employee’s intent or action directly threatens the organisation’s security posture.
- ✓
Report the violation to HR for disciplinary action per the existing policy
Why this is correct
The Acceptable Use Policy already prohibits personal browsing on corporate laptops, so the streaming is a confirmed policy breach. Reporting to HR applies the established disciplinary process rather than inventing new controls or ignoring the violation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.