Courseiva
mediumMultiple Choice

200-201 Practice Question: An analyst discovers that an employee has been…

An analyst discovers that an employee has been using company-issued laptops to run a personal cryptocurrency mining software. Which policy violation has occurred?

⚠ Common exam trap

The trap here is conflating a policy violation with an incident response or change management issue — candidates may pick Incident Response because mining is 'an incident,' but the question asks which policy the employee violated, and that is the Acceptable Use Policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acceptable Use Policy

An Acceptable Use Policy (AUP) defines how company-owned assets and networks may be used, and typically prohibits personal or unauthorized activities such as cryptocurrency mining on corporate laptops. Running mining software on company hardware violates the AUP because it misuses corporate resources for personal gain and can degrade performance or introduce security risk. The other policies address incident handling, change control, and data handling — none of which directly govern employee use of company devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident Response Policy

    Why it's wrong here

    Incident response covers detecting, containing and recovering from security events, not the underlying employee conduct. It is tempting because mining is a security event requiring response, but the question asks which policy the employee violated; acceptable use of company assets is the applicable policy.

  • ✗

    Change Management Policy

    Why it's wrong here

    Change management governs controlled modification of production systems through approval and scheduling, not employee misuse of an endpoint. It is tempting because installing mining software is an unauthorised change, but the violation is acceptable use of company-issued equipment, not a change-control breach.

  • ✓

    Acceptable Use Policy

    Why this is correct

    Cryptocurrency mining on company hardware falls outside permitted business use, breaching the Acceptable Use Policy that defines authorised employee behaviour with organisational assets. The policy explicitly governs how company-issued laptops may be used, so unauthorised personal mining constitutes a direct violation of its usage constraints.

  • ✗

    Data classification policy

    Why it's wrong here

    Data classification governs labelling and handling of information assets, not acceptable use of corporate hardware. It is tempting because mining consumes resources and touches data, but no classification label is breached; the acceptable use or asset usage policy is the correct violation.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 200-201

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst discovers that an employee has been sharing login credentials with coworkers. Which policy violation is this?

medium
  • A.Remote Access Policy violation
  • B.Incident Response Policy violation
  • C.Data Classification Policy violation
  • ✓ D.Acceptable Use Policy violation

Why D: Sharing login credentials violates the Acceptable Use Policy (AUP), which defines how employees may use company systems and data. The AUP typically prohibits password sharing because it undermines non-repudiation and access control, as each user should have unique credentials for accountability. This is a direct breach of acceptable behavior, not a failure of remote access, incident response, or data classification procedures.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.