220-1102 Operational Procedures Practice Question
A company drafts a policy that defines acceptable use of company-provided devices, including internet browsing, email etiquette, and prohibited software. Which type of policy is this?
⚠ Common exam trap
It's easy for candidates to confuse an Acceptable Use Policy with a Password Policy because both are security-related, but the question's specific mention of internet browsing and software restrictions clearly points to an AUP, not password rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acceptable Use Policy
The policy described explicitly governs acceptable use of company-provided devices, covering internet browsing, email etiquette, and prohibited software. This directly matches the definition of an Acceptable Use Policy (AUP), which outlines what users may and may not do with organizational IT resources. An AUP is a foundational operational procedure for enforcing security and compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Acceptable Use Policy
Why this is correct
An Acceptable Use Policy (AUP) is the definitive document that delineates permitted and prohibited actions when employees interact with company-owned systems, networks, email, internet, and data. It establishes baselines for data confidentiality, personal use, intellectual property protection, and security responsibilities, and typically includes enforcement mechanisms and disciplinary consequences for non-compliance.
- ✗
Password Policy
Why it's wrong here
A Password Policy is not about defining acceptable use of resources; instead, it specifies minimum password length, complexity, rotation intervals, lockout thresholds, and often mandates multi-factor authentication. It protects authentication integrity and prevents credential-based attacks, but it does not govern what users may do with company devices, networks, or data.
- ✗
Change Management Policy
Why it's wrong here
A Change Management Policy governs the lifecycle of IT infrastructure modifications, such as patches, upgrades, configurations, and rollbacks, using a formal request, impact assessment, approval, and implementation workflow. Its purpose is to reduce the risk of service disruption and ensure traceability of system changes, rather than to define how users should behave when utilizing corporate assets.
- ✗
Disaster Recovery Policy
Why it's wrong here
A Disaster Recovery Policy focuses on preparing for and recovering from catastrophic incidents such as ransomware attacks, natural disasters, or hardware failures, outlining backup schedules, failover procedures, recovery time objectives (RTOs), and recovery point objectives (RPOs). It is a reactive continuity plan for restoring IT operations, not a code of conduct for day-to-day acceptable use of company resources.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
AUP
An Acceptable Use Policy (AUP) is a set of rules that define how users are allowed to access and use a company's network, devices, and internet connection.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.