Courseiva
mediumMultiple Select

200-201 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for implementing a security policy?

⚠ Common exam trap

Cisco often tests the misconception that security policies are static, one-time documents, when in fact they require periodic review and management buy-in to remain effective and enforceable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review and update the policy annually

Option D is correct because security policies must be reviewed and updated annually (or whenever significant changes occur in the threat landscape, technology, or business operations) to remain relevant and effective; a stale policy can leave the organization exposed to new risks. Option E is correct because obtaining management approval and support is essential: without executive sponsorship, the policy lacks authority, funding, and the ability to enforce compliance across the organization. Option A is incorrect because technical jargon reduces readability and understanding for non-technical staff, undermining policy adoption. Option B is incorrect because avoiding enforcement does not promote genuine compliance; policies require consistent enforcement to be effective. Option C is incorrect because writing a policy once and never changing it ignores evolving threats, regulations, and business needs, making the policy obsolete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use technical jargon to ensure precision

    Why it's wrong here

    Technical jargon alienates the non-technical staff who must follow the policy, undermining comprehension and compliance. Plain language is required for enforceable security policies. Jargon suits narrow technical standards or configuration baselines aimed at specialists, not organisation-wide policy documents.

  • ✗

    Avoid enforcement to promote user compliance

    Why it's wrong here

    Avoiding enforcement leaves policy violations undetected and unaddressed, so the policy cannot shape behaviour or satisfy governance requirements. Enforcement mechanisms such as conditional access and compliance policies exist precisely to apply controls automatically. This approach would only suit awareness campaigns where voluntary adoption is the goal and no regulatory or security obligation demands mandatory adherence.

  • ✗

    Write the policy once and never change it

    Why it's wrong here

    A static policy cannot address evolving threats, regulatory updates or organisational change, so it will drift out of alignment with the environment it governs. Writing it once is tempting because it minimises ongoing effort, and a fixed document suits a stable, low-risk context where no review cycle is mandated.

  • ✓

    Review and update the policy annually

    Why this is correct

    Scheduled annual review keeps the policy aligned with evolving threats, technology and business changes. Without periodic revision, controls become stale and gaps emerge, so regular review is a recognised lifecycle best practice for maintaining policy effectiveness.

  • ✓

    Obtain management approval and support

    Why this is correct

    Management approval and support secure the budget, authority and cross-departmental cooperation a security policy needs to be enforced rather than ignored. Without executive sponsorship, the policy lacks the mandate to impose controls on unwilling business units, so this satisfies the stem's requirement for an implementable governance practice.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.