Courseiva
mediumMatchingObjective-mapped

CISSP Match each security policy to its purpose. Practice Question

Match each security policy to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines allowed use of organizational assets

Categorizes data based on sensitivity

Procedures for handling security incidents

Rules for password creation and management

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Acceptable Use Policy: Defines acceptable use of organizational resources.

Security policies provide organizational guidance. The Acceptable Use Policy details proper use of IT resources; the Information Security Policy sets the overall security vision; the Data Classification Policy categorizes data by sensitivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Acceptable Use Policy: Defines acceptable use of organizational resources.

    Why this is correct

    An Acceptable Use Policy (AUP) explicitly outlines the proper and prohibited ways employees, contractors, and other authorized users can utilize organizational resources, including computers, networks, internet access, and software. It establishes clear boundaries for resource engagement to protect organizational data, maintain productivity, and ensure legal and regulatory compliance, often detailing consequences for violations.

  • Acceptable Use Policy: High-level statement of management commitment to security.

    Why it's wrong here

    An Acceptable Use Policy (AUP) focuses on governing user behavior and the specific, permissible ways individuals interact with organizational IT assets and information. It is not designed to be a high-level declaration of management's overarching commitment to safeguarding information assets; that foundational, strategic role is fulfilled by the Information Security Policy, which sets the enterprise-wide security posture.

  • Information Security Policy: High-level statement of management commitment to security.

    Why this is correct

    The Information Security Policy serves as the foundational document, articulating management's overarching commitment to protecting organizational information assets across the enterprise. It establishes the strategic direction for security, outlining the organization's philosophy, objectives, and responsibilities regarding the confidentiality, integrity, and availability of data, thereby setting the stage for all subordinate security policies and standards.

  • Data Classification Policy: Defines acceptable use of organizational resources.

    Why it's wrong here

    A Data Classification Policy's primary function is to categorize information based on its sensitivity, value, and criticality, dictating appropriate protection measures. It does not address the permissible ways users interact with or utilize organizational IT assets such as networks, email, or hardware; that specific scope falls under the Acceptable Use Policy, which governs user conduct and resource engagement.

  • Data Classification Policy: Defines levels of data sensitivity and handling.

    Why this is correct

    A Data Classification Policy systematically categorizes organizational data into distinct levels, such as public, internal, confidential, or restricted, based on its sensitivity, value, and potential impact if compromised. This policy then dictates the specific security controls, handling procedures, storage requirements, and access restrictions appropriate for each classification level throughout its entire lifecycle.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.