200-201 Security Policies and Procedures Practice Question
A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?
⚠ Common exam trap
Candidates often confuse the AUP with other policies like the NDA, which also govern behavior but focus on confidentiality rather than asset use.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acceptable Use Policy (AUP)
The Acceptable Use Policy (AUP) is designed to outline the rules and guidelines for using company assets. It typically covers what is allowed and prohibited, and the consequences of violations. This aligns with the scenario's requirement to define acceptable use of computers, networks, and data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service Level Agreement (SLA)
Why it's wrong here
An SLA is a contract between a service provider and a customer that defines the level of service expected. It does not govern employee behavior regarding asset use. Therefore, it is not the correct document for outlining acceptable use rules.
- ✗
Non-Disclosure Agreement (NDA)
Why it's wrong here
An NDA is a legal contract that prohibits sharing confidential information. While it may be part of the overall policy framework, it does not define acceptable use of assets. The scenario specifically asks for rules on using company assets, which is the AUP's purpose.
- ✗
Incident Response Plan (IRP)
Why it's wrong here
The IRP outlines the steps to take during a security incident. It does not specify acceptable use of assets. The scenario is about rules for employee behavior, not incident handling, so the IRP is not the correct document.
- ✓
Acceptable Use Policy (AUP)
Why this is correct
The Acceptable Use Policy (AUP) defines how employees may use company assets, including computers and networks. It sets expectations for behavior and consequences for violations. In this scenario, the AUP is the document that outlines these rules, making it the correct choice.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.