easyMultiple Select
200-201 Practice Question: An organization's security policy defines…
An organization's security policy defines acceptable use of corporate email. Which THREE of the following actions are typically prohibited?
⚠ Common exam trap
Cisco often tests the distinction between actions that are 'typically prohibited' versus those that are merely discouraged or context-dependent, leading candidates to over-select options like personal newsletter subscriptions (Option A) that are not universally banned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sending personal emails using the corporate account.
Option C is correct because sending personal emails through a corporate account violates acceptable use policies, which restrict company resources to business purposes and expose the organization to liability and data leakage. Option D is correct because forwarding corporate email to personal external accounts exfiltrates potentially confidential or regulated data outside the organization's controlled environment, a common policy prohibition. Option E is correct because transmitting sensitive customer data without encryption breaches data protection requirements (e.g., GDPR, HIPAA, PCI DSS) and typical acceptable use policies mandating encryption for sensitive information. Option A does not belong because subscribing to personal newsletters is a minor personal use that many policies tolerate or address separately, not a typical outright prohibition. Option B does not belong because emailing IT support for assistance is a legitimate business use of corporate email and is never prohibited.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using email to subscribe to personal newsletters.
Why it's wrong here
Personal newsletter subscriptions consume corporate bandwidth and expose the address to external mailing lists, breaching acceptable-use terms. It is tempting because incidental personal use is often tolerated informally, and the policy would permit it only where an employer explicitly allows reasonable personal email use.
- ✗
Emailing the IT support for assistance.
Why it's wrong here
Contacting IT support is a sanctioned, encouraged use of corporate email, so it cannot be prohibited. It is tempting because the option sounds like ordinary internal correspondence that a strict policy might restrict, yet it would be the correct choice only if the question asked which actions are permitted.
- ✓
Sending personal emails using the corporate account.
Why this is correct
Corporate accounts are provided for business purposes, so personal use breaches the acceptable-use policy and exposes the organisation to data loss and reputational risk. Sending personal email from the corporate account violates the policy's scope-of-use constraint, making it a typically prohibited action.
- ✓
Forwarding corporate emails to personal external accounts.
Why this is correct
Forwarding corporate email to personal external accounts moves organisational data outside the controlled environment, bypassing retention, monitoring and data-loss prevention controls. This directly breaches the acceptable-use policy's restriction on exfiltrating business communications, so it is typically prohibited.
- ✓
Using email to send sensitive customer data without encryption.
Why this is correct
Sending unencrypted sensitive customer data breaches confidentiality controls that acceptable-use policies mandate. Encryption protects data in transit across untrusted networks; without it, interception exposes personally identifiable information, violating regulatory obligations such as UK GDPR. This directly satisfies the policy's prohibition on insecure handling of regulated data, making the action prohibited.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.