Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A small business owner wants to ensure that employees follow a consistent and documented process when handling sensitive customer data. Which type of document should the technician recommend to outline the step-by-step procedures?

⚠ Common exam trap

It's easy for candidates to confuse an Acceptable Use Policy (AUP) with a procedural document, but an AUP only sets behavioral boundaries, not the detailed step-by-step workflow required for consistent data handling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standard Operating Procedure

A Standard Operating Procedure (SOP) is the correct document because it provides a detailed, step-by-step set of instructions that employees must follow to consistently handle sensitive customer data. SOPs are designed to ensure compliance with internal policies and regulatory requirements by standardizing routine operational tasks, such as data access, encryption, and disposal procedures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Acceptable Use Policy

    Why it's wrong here

    An Acceptable Use Policy (AUP) defines the boundaries for how employees may interact with company technology, such as internet browsing, email, and hardware usage. It focuses on permitted versus prohibited activities and often includes consequences for misuse, but it does not specify the step-by-step routines required for handling sensitive data. While an AUP may state that data must be protected, it lacks the procedural detail needed to ensure consistent execution of tasks like data classification, encryption, or secure disposal—making it insufficient for standardizing daily data handling.

  • ✗

    Incident Response Plan

    Why it's wrong here

    An Incident Response Plan (IRP) is a reactive framework that takes effect when a security breach, malware infection, or other unexpected anomaly is detected. It prescribes roles, detection methods, containment strategies, eradication steps, and recovery procedures to minimize impact and restore normal operations. Because an IRP is designed for emergency situations, it is not applicable to routine data handling tasks; it does not provide ongoing instructions for how employees should manage sensitive data under normal business conditions. The correct document for consistent day-to-day operations is a standardized procedure, not a contingency plan.

  • ✓

    Standard Operating Procedure

    Why this is correct

    A Standard Operating Procedure (SOP) is a detailed, step-by-step set of instructions that ensures tasks are performed consistently, safely, and in compliance with organizational or regulatory requirements. For handling sensitive data, an SOP would specify exact actions such as how to encrypt files, whom to notify for access approval, how to log data transfers, and the proper method for securely erasing information. This procedural precision guarantees that every employee executes the workflow identically, reducing errors, preventing unauthorized exposure, and providing auditable evidence of due diligence. It is the appropriate document for ensuring employees follow a prescribed routine in their daily work.

  • ✗

    Service Level Agreement

    Why it's wrong here

    A Service Level Agreement (SLA) is a contractual commitment between a service provider and a customer that defines measurable performance standards, such as uptime percentages, response times, and availability targets. It governs the relationship between two parties and sets expectations for service quality, but it does not dictate how employees should interact with data internally. An SLA is not an internal procedure manual; it cannot provide the detailed handling steps needed for everyday tasks like data entry, file storage, or data sharing. Thus, while an SLA is valuable for vendor management, it is irrelevant to ensuring employees follow internal data-handling practices.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.