Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)

⚠ Common exam trap

The trap here is thinking that technical details such as network diagrams or vulnerability lists belong in an AUP, when they are actually part of separate technical or operational documents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Consequences for policy violations

An Acceptable Use Policy must clearly define acceptable and unacceptable use of organizational assets and specify consequences for violations. These elements set expectations and enable enforcement. Technical details like network diagrams, incident response procedures, and vulnerability lists belong in other documents and are not core components of an AUP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List of all software vulnerabilities and patches

    Why it's wrong here

    A list of software vulnerabilities and patches is a technical operational document, not part of an AUP. The AUP is a policy that defines user expectations and prohibitions. Vulnerability management details change frequently and are irrelevant to acceptable use. Therefore, this is not an essential element of an AUP.

  • ✗

    Detailed network diagram of the organization's infrastructure

    Why it's wrong here

    A network diagram is not a component of an AUP. While it may be useful for technical documentation, the AUP focuses on user behavior and responsibilities, not on technical topology. Including such details could expose sensitive information and is not relevant to acceptable use. Therefore, it is not an essential element of an AUP.

  • ✓

    Consequences for policy violations

    Why this is correct

    An effective AUP must outline the consequences of violating the policy, which may include disciplinary action, termination, or legal action. This element deters misuse and ensures consistent enforcement. It also protects the organization legally by establishing that violations are taken seriously. Thus, consequences are an essential component of an AUP.

  • ✓

    Definition of acceptable and unacceptable use of organizational assets

    Why this is correct

    An AUP must clearly define what constitutes acceptable and unacceptable use of organizational assets, such as computers, networks, and data. This definition sets expectations for employees and provides a basis for enforcement. Without it, users may not know what behaviors are prohibited, leading to policy violations and security risks.

  • ✗

    Step-by-step incident response procedures

    Why it's wrong here

    Incident response procedures belong in an Incident Response Plan, not in an AUP. The AUP governs user conduct and acceptable use of resources. Mixing incident response steps into the AUP would confuse its purpose and likely omit necessary technical details. Hence, it is not an essential component of an AUP.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.