Courseiva
mediumMultiple Select

200-201 Practice Question: Which THREE of the following are best practices…

Which THREE of the following are best practices for creating and maintaining security policies? (Choose three.)

⚠ Common exam trap

Cisco often tests the misconception that security policies should be restricted to security staff only, but the correct approach is that policies must be accessible to all employees to ensure awareness and compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain approval from senior management.

Option B is correct because security policies derive their authority from executive endorsement; obtaining approval from senior management ensures the policies are formally sanctioned, funded, and enforceable across the organization. Option C is correct because policies are only effective if the people they govern understand them, so providing training on policies to all employees ensures awareness, accountability, and consistent compliance. Option D is correct because reviewing and updating policies annually keeps them aligned with changes in business operations, technology, regulations, and threat landscape, preventing outdated or ineffective controls. Option A is not a best practice because developing policies in isolation by the security team excludes key stakeholders such as legal, HR, IT, and business units, reducing practicality and buy-in. Option E is not a best practice because storing policies in a secure location accessible only to security staff undermines the need for organization-wide visibility, awareness, and training that make policies effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Develop policies in isolation by the security team.

    Why it's wrong here

    Drafting policies solely within the security team omits business units, legal and IT stakeholders whose operational constraints the policy must reflect, producing unworkable rules. It tempts because security owns policy content, yet isolation is correct only for narrow technical standards, not organisation-wide policies.

  • ✓

    Obtain approval from senior management.

    Why this is correct

    Senior management approval secures the authority and budget needed for enforcement, satisfying the governance requirement that policies carry organisational weight. Without executive endorsement, security policies lack the mandate to compel compliance across departments, making this a recognised best practice for establishing and maintaining them.

  • ✓

    Provide training on policies to all employees.

    Why this is correct

    Training all employees ensures policies are understood and consistently applied, satisfying the best-practise requirement for awareness and communication. Security policies fail without user comprehension, so ongoing education reduces misconfiguration and human error, directly supporting maintenance of the policy framework across the organisation.

  • ✓

    Review and update policies annually.

    Why this is correct

    Annual review satisfies the stem's maintenance requirement by forcing periodic reassessment of controls against changed threats, regulations and business processes. Policies left unrevised decay into inaccurate documentation that staff cannot follow, so a scheduled yearly cycle keeps them aligned with current risk appetite and audit expectations.

  • ✗

    Store policies in a secure location accessible only to security staff.

    Why it's wrong here

    Restricting policy access to security staff prevents the workforce from reading the rules they must follow, undermining awareness and compliance. It tempts because policies are sensitive documents, but confidentiality applies to incident data or credentials, not to the policies themselves.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.