Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician needs to create a document that defines the step-by-step process for escalating a security incident within the IT department. Which type of document should be created?

⚠ Common exam trap

Watch out — candidates often confuse a policy (AUP) with a procedure (SOP), mistakenly thinking that a high-level rule document is sufficient for a detailed step-by-step process, when in fact an SOP is the only document that provides actionable, sequential instructions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standard Operating Procedure (SOP)

A Standard Operating Procedure (SOP) is the correct document because it provides a detailed, step-by-step sequence of actions to be followed consistently for a specific operational task, such as escalating a security incident. Unlike a policy or agreement, an SOP is designed to standardize procedures, ensuring that all help desk technicians follow the same escalation path, notification hierarchy, and documentation requirements during a security incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Standard Operating Procedure (SOP)

    Why this is correct

    An SOP is the definitive document type for capturing a step-by-step process, prescribing the exact sequence of actions, decision points, roles, and responsibilities required to complete a task consistently. In an IT support context, an SOP for incident escalation would detail, for example, the specific conditions that trigger escalation, who must be notified at each tier, and the communication templates to use. This codification ensures operational consistency, auditability, and compliance with internal standards or regulatory requirements.

  • ✗

    Acceptable Use Policy (AUP)

    Why it's wrong here

    An AUP is a policy document that defines what users may and may not do with an organization's IT assets, such as acceptable internet usage, email conduct, and handling of credentials. It establishes behavioral boundaries and consequences for violations, but it does not contain procedural instructions for performing a technical task or workflow. While an AUP might state that users must not share passwords, it never walks through the operational steps of, say, escalating an incident.

  • ✗

    Service Level Agreement (SLA)

    Why it's wrong here

    An SLA is a contractual instrument between a service provider and a customer that specifies expected service levels, such as uptime percentages, response times, and resolution targets, along with remedies or penalties for non-compliance. It defines the measurable performance commitments, not the internal operating procedures used to achieve them. For instance, an SLA might mandate a 15-minute response time for critical incidents, but it would not describe how an IT technician should execute an escalation workflow.

  • ✗

    Business Continuity Plan (BCP)

    Why it's wrong here

    A BCP is a strategic document that outlines how an organization will maintain or rapidly restore critical functions during a disruptive event, such as natural disasters, cyberattacks, or infrastructure failures. It focuses on continuity, redundancy, and recovery objectives, not on routine operational processes like incident escalation during normal business hours. A BCP may include escalation in an emergency context, but its purpose is business survival, whereas the question asks about a document defining the step-by-step process for a standard procedure.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.