220-1102 Operational Procedures Practice Question
A small business owner wants to ensure that employees follow a consistent and documented process when handling sensitive customer data. Which type of document should the technician recommend to outline the step-by-step procedures?
⚠ Common exam trap
It's easy for candidates to confuse an Acceptable Use Policy (AUP) with a procedural document, but an AUP only sets behavioral boundaries, not the detailed step-by-step workflow required for consistent data handling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard Operating Procedure
A Standard Operating Procedure (SOP) is the correct document because it provides a detailed, step-by-step set of instructions that employees must follow to consistently handle sensitive customer data. SOPs are designed to ensure compliance with internal policies and regulatory requirements by standardizing routine operational tasks, such as data access, encryption, and disposal procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Acceptable Use Policy
Why it's wrong here
An Acceptable Use Policy (AUP) defines the boundaries for how employees may interact with company technology, such as internet browsing, email, and hardware usage. It focuses on permitted versus prohibited activities and often includes consequences for misuse, but it does not specify the step-by-step routines required for handling sensitive data. While an AUP may state that data must be protected, it lacks the procedural detail needed to ensure consistent execution of tasks like data classification, encryption, or secure disposal—making it insufficient for standardizing daily data handling.
- ✗
Incident Response Plan
Why it's wrong here
An Incident Response Plan (IRP) is a reactive framework that takes effect when a security breach, malware infection, or other unexpected anomaly is detected. It prescribes roles, detection methods, containment strategies, eradication steps, and recovery procedures to minimize impact and restore normal operations. Because an IRP is designed for emergency situations, it is not applicable to routine data handling tasks; it does not provide ongoing instructions for how employees should manage sensitive data under normal business conditions. The correct document for consistent day-to-day operations is a standardized procedure, not a contingency plan.
- ✓
Standard Operating Procedure
Why this is correct
A Standard Operating Procedure (SOP) is a detailed, step-by-step set of instructions that ensures tasks are performed consistently, safely, and in compliance with organizational or regulatory requirements. For handling sensitive data, an SOP would specify exact actions such as how to encrypt files, whom to notify for access approval, how to log data transfers, and the proper method for securely erasing information. This procedural precision guarantees that every employee executes the workflow identically, reducing errors, preventing unauthorized exposure, and providing auditable evidence of due diligence. It is the appropriate document for ensuring employees follow a prescribed routine in their daily work.
- ✗
Service Level Agreement
Why it's wrong here
A Service Level Agreement (SLA) is a contractual commitment between a service provider and a customer that defines measurable performance standards, such as uptime percentages, response times, and availability targets. It governs the relationship between two parties and sets expectations for service quality, but it does not dictate how employees should interact with data internally. An SLA is not an internal procedure manual; it cannot provide the detailed handling steps needed for everyday tasks like data entry, file storage, or data sharing. Thus, while an SLA is valuable for vendor management, it is irrelevant to ensuring employees follow internal data-handling practices.
Go deeper
Related to this question
Learn chapter
Basic Compliance: GDPR, HIPAA, PCI-DSS
Key term
Standard Operating Procedure
A Standard Operating Procedure is a detailed, written set of step-by-step instructions that describes how to perform a specific task or process consistently and safely.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.