Courseiva

200-201 Security Policies and Procedures Practice Question

A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?

⚠ Common exam trap

Many exam-takers confuse NIST SP 800-37, which describes the Risk Management Framework process, with NIST SP 800-53, which actually contains the control catalog.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NIST SP 800-53

NIST SP 800-53 is the definitive catalog of security and privacy controls for federal information systems and organizations. It is widely adopted by private sector organizations to build robust security programs. The other NIST publications focus on incident handling, risk assessment, and the risk management framework, respectively, and do not provide the comprehensive control catalog needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NIST SP 800-53

    Why this is correct

    NIST SP 800-53, 'Security and Privacy Controls for Information Systems and Organizations,' provides a comprehensive catalog of security and privacy controls. It is the primary source for federal agencies and many private organizations to select and implement controls. In this scenario, the retail company needs a control catalog, making SP 800-53 the correct reference.

  • ✗

    NIST SP 800-61

    Why it's wrong here

    NIST SP 800-61 is the 'Computer Security Incident Handling Guide.' It provides guidance on incident response lifecycle, from preparation to post-incident activity. While valuable for incident response planning, it does not offer a comprehensive catalog of security and privacy controls. Therefore, it does not meet the company's need for a control framework.

  • ✗

    NIST SP 800-37

    Why it's wrong here

    NIST SP 800-37 is the 'Risk Management Framework for Information Systems and Organizations.' It provides a disciplined, structured, and flexible process for managing security and privacy risk. While it references controls from SP 800-53, it does not itself contain the comprehensive control catalog. Therefore, it is not the best source for control listings.

  • ✗

    NIST SP 800-30

    Why it's wrong here

    NIST SP 800-30 is the 'Guide for Conducting Risk Assessments.' It describes the risk assessment process, including threat identification, vulnerability analysis, and impact determination. This publication is focused on risk assessment methodology, not on providing a catalog of security and privacy controls. Thus, it is not the appropriate reference for control selection.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.