220-1102 Operational Procedures Practice Question
A small business wants to ensure that all employees formally acknowledge the company's acceptable use policy (AUP) for computers and the internet. Which method provides the most reliable record of employee acknowledgment?
⚠ Common exam trap
A common mix-up: candidates choose email or intranet posting because they seem efficient, but the exam emphasizes that only a signed form (physical or electronic) provides the legally defensible proof of acknowledgment required for compliance and disciplinary actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Have employees sign an acknowledgment form
A signed acknowledgment form provides a verifiable, non-repudiable record that each employee has read and agreed to the AUP. Unlike digital methods, a physical or electronically signed document with a timestamp and signature cannot be easily disputed or automatically dismissed as spam, ensuring legal and audit compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Post the policy on the company intranet
Why it's wrong here
Posting the policy on the company intranet is a passive dissemination method—it merely makes the document available for voluntary viewing. The organization cannot verify that any specific employee actually accessed, read, or understood the policy, nor capture their affirmative consent. Without mandatory access logs or an integrated acknowledgment workflow, this approach produces no auditable evidence of individual compliance and fails to meet policy acknowledgment requirements.
- ✓
Have employees sign an acknowledgment form
Why this is correct
Having employees sign an acknowledgment form is the only option that creates a verifiable, legally recognizable record of informed consent. A physical or electronic signature constitutes an affirmative act by the employee, tying their identity, the policy version, and the date/time of acceptance. This record can be retained as audit evidence and used to demonstrate individual accountability during internal investigations, certification audits, or legal proceedings, satisfying the requirement to prove each employee formally acknowledged the policy.
- ✗
Send an email to all employees with the policy attached
Why it's wrong here
Sending an email with the policy attached only proves that a message was transmitted to an address; it does not prove that the employee opened, read, or agreed to the content. Email delivery reports and read receipts are unreliable because recipients can disable read receipts, open the message without downloading the attachment, or have the email filtered into spam. This method lacks any positive, signed confirmation from the employee, so the organization cannot produce a non-repudiable record of acknowledgment.
- ✗
Verbally explain the policy at a team meeting
Why it's wrong here
Verbally explaining the policy at a team meeting relies on undocumented oral communication, which leaves no tangible proof that each attendee understood or formally accepted the policy. Even if a sign-in sheet records attendance, it only shows presence, not comprehension, agreement, or acknowledgment of the specific policy terms. In a dispute or audit, there is no timestamped, signed record linking each employee to the content, making this the weakest and least defensible method of obtaining formal acknowledgment.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
AUP
An Acceptable Use Policy (AUP) is a set of rules that define how users are allowed to access and use a company's network, devices, and internet connection.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.