200-201 Security Policies and Procedures Practice Question
A mid-size healthcare company has completed its annual review of security documentation. The CISO asks the governance team to align the documents into a clear hierarchy, where a single high-level document states the organization's overall security intentions and direction, and all subordinate documents must conform to it. Which document should the governance team treat as the highest-level authority?
⚠ Common exam trap
The trap here is assuming that the most technically detailed document, such as a hardening standard or procedure, is the governing authority rather than recognizing that the policy sits at the top of the documentation hierarchy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policy
The security policy is the foundational, management-approved statement of security intent, scope, and objectives, and it drives every standard, procedure, and guideline beneath it. Standards define mandatory requirements, procedures describe exact steps, and guidelines provide optional advice. Only the security policy functions as the single highest-level authority to which all subordinate documentation must conform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security standard
Why it's wrong here
A standard is mandatory and specific, such as requiring AES-256 for data at rest, but it sits below the policy. Standards translate policy intent into measurable requirements and must themselves comply with the policy. Treating a standard as the highest-level authority would invert the hierarchy, since a standard cannot define the organization's overall security intentions.
- ✗
Security guideline
Why it's wrong here
A guideline offers recommended, non-mandatory advice about how to achieve policy objectives. Because it is discretionary rather than authoritative, it cannot be the document that all other documents must conform to. Placing a guideline at the top of the hierarchy would leave the organization without enforceable, mandatory security direction.
- ✗
Security procedure
Why it's wrong here
A procedure is a detailed, step-by-step instruction for carrying out a task, such as how to onboard a user account. Procedures are operational and are derived from standards and policy. They are far too granular to express the organization's overall security direction, so a procedure cannot serve as the highest-level governance document.
- ✓
Security policy
Why this is correct
A security policy is the top-level governance document that states management's intent, scope, and overall security objectives for the organization. Every standard, procedure, and guideline must be consistent with it. Because the scenario requires one high-level document that all subordinate documents conform to, the security policy is the correct authority to treat as the highest-level document.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.