Courseiva
easyMultiple Choice

200-201 Practice Question: A company's security policy states that employees…

A company's security policy states that employees must not use corporate laptops for personal web browsing. An employee is found to have streamed video during work hours, consuming significant bandwidth. What is the best course of action?

⚠ Common exam trap

200-201 often tests the boundary between technical response and HR/legal process — candidates pick 'terminate' or 'warn' because they sound decisive, but the correct answer is always to follow the documented policy and route through HR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the violation to HR for disciplinary action per the existing policy

When a security policy already exists and an employee is found to have violated it, the correct action is to follow the established disciplinary process — typically reporting the violation to HR so the organisation's policy is enforced consistently. This preserves due process, creates an auditable record, and avoids ad-hoc decisions by the security team. Terminating immediately or ignoring the violation both undermine the policy's authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Give a verbal warning and take no further action

    Why it's wrong here

    A verbal warning alone leaves the policy violation unrecorded and unenforced, so the bandwidth misuse and repeat risk persist. Verbal counselling suits trivial first-time breaches; here the documented policy breach and resource impact warrant formal disciplinary steps under the acceptable-use policy.

  • ✗

    Update the policy to allow streaming under certain conditions

    Why it's wrong here

    Rewriting the policy to permit streaming legitimises the behaviour instead of addressing the violation, and ignores the bandwidth and acceptable-use controls already in force. Policy revision suits deliberate business change after risk assessment, not as a response to an employee breaching an existing rule.

  • ✗

    Immediately terminate the employee

    Why it's wrong here

    Immediate termination disregards the principle of proportionality in security policy enforcement; the violation is a bandwidth-consumption policy breach, not a malicious act that compromised data confidentiality or system integrity. This option is tempting because termination is the correct response for severe infractions such as deliberate data exfiltration or installing unauthorised remote-access tools, where the employee’s intent or action directly threatens the organisation’s security posture.

  • ✓

    Report the violation to HR for disciplinary action per the existing policy

    Why this is correct

    The Acceptable Use Policy already prohibits personal browsing on corporate laptops, so the streaming is a confirmed policy breach. Reporting to HR applies the established disciplinary process rather than inventing new controls or ignoring the violation.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.