mediumMultiple Choice
200-201 Practice Question: A security analyst discovers that an employee has…
A security analyst discovers that an employee has been sharing login credentials with coworkers. Which policy violation is this?
⚠ Common exam trap
Cisco often tests the distinction between policies by making candidates confuse a data classification violation (handling sensitive data incorrectly) with an acceptable use violation (improper use of credentials or systems).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acceptable Use Policy violation
Sharing login credentials violates the Acceptable Use Policy (AUP), which defines how employees may use company systems and data. The AUP typically prohibits password sharing because it undermines non-repudiation and access control, as each user should have unique credentials for accountability. This is a direct breach of acceptable behavior, not a failure of remote access, incident response, or data classification procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remote Access Policy violation
Why it's wrong here
A remote access policy governs how external connections to the network are made and secured, not internal credential sharing between colleagues. It applies when users connect remotely, so it does not cover this on-site account-sharing breach.
- ✗
Incident Response Policy violation
Why it's wrong here
Sharing credentials breaches the Acceptable Use Policy governing account usage, not the Incident Response Policy, which defines how incidents are detected, escalated and contained. It tempts because credential misuse can trigger an incident, but IR policy addresses handling the event, not the underlying user conduct rule.
- ✗
Data Classification Policy violation
Why it's wrong here
Sharing login credentials breaches authentication and access control rules, not data handling tiers. A data classification policy governs how information is labelled, handled and protected by sensitivity level — it would apply if the employee emailed confidential records to an unauthorised recipient or stored them in an unapproved location.
- ✓
Acceptable Use Policy violation
Why this is correct
Sharing login credentials breaches the acceptable use policy, which governs how employees may use organisational accounts and systems. Credential sharing violates the accountability and non-transfer clauses such policies define, making this the applicable violation category.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.