Courseiva
easyMultiple SelectObjective-mapped

CISSP Practice Question: Which TWO are essential components of a security…

Which TWO are essential components of a security policy framework?

⚠ Common exam trap

Many exam-takers confuse operational documents (flowcharts, diagrams, key lengths) with the foundational governance components of a policy framework, which must always include scope and accountability to be enforceable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Roles and responsibilities

Roles and responsibilities (D) are essential because they define who is accountable for implementing, maintaining, and enforcing the security policy. Without clear assignment of duties, policy execution becomes unenforceable and audit trails lack ownership, violating the separation of duties principle central to the Security and Risk Management domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Specific encryption key lengths

    Why it's wrong here

    Specific encryption key lengths are technical implementation details that belong in security standards or guidelines, not within the high-level security policy framework itself. A policy sets the overarching requirement for strong encryption to protect sensitive data, but specifying granular technical parameters like 'AES-256' or 'RSA 2048-bit' would make the policy overly prescriptive, difficult to maintain, and prone to rapid obsolescence as technology evolves. Policies focus on 'what' must be achieved, leaving 'how' to supporting documentation.

  • Incident response flowcharts

    Why it's wrong here

    Incident response flowcharts are detailed, step-by-step instructions that form part of security procedures, not the foundational policy document. While a security policy mandates the establishment of an incident response capability and defines high-level objectives, the specific visual representations and sequential actions for handling incidents are operational procedures. Policies define the organizational commitment and requirements for incident management, whereas flowcharts provide the actionable, granular steps for personnel to follow during an event.

  • Network topology diagrams

    Why it's wrong here

    Network topology diagrams are operational or architectural documentation, providing a visual representation of the network's physical or logical layout. These diagrams are essential for network design, management, and troubleshooting, and they support the implementation of security controls. However, they are not intrinsic components of the security policy framework itself, which focuses on establishing rules, directives, and responsibilities rather than depicting infrastructure configurations.

  • Roles and responsibilities

    Why this is correct

    Defining roles and responsibilities is an essential component of a security policy framework because it assigns accountability and clarifies who is responsible for specific security tasks and decisions. This ensures that all personnel understand their obligations regarding information security, from data ownership and system administration to compliance monitoring. Without clearly delineated roles, policies lack enforceability and the organization cannot effectively manage its security posture, leading to potential gaps and failures in implementation.

  • Statement of scope

    Why this is correct

    A clear statement of scope is fundamental to a security policy framework as it precisely defines what the policy applies to, including specific assets, systems, data, personnel, and organizational boundaries. This clarity prevents ambiguity and ensures that the policy's directives are consistently applied across the intended environment. Without a well-defined scope, the policy's applicability could be misinterpreted, leading to inconsistent security practices or critical areas being inadvertently excluded from coverage.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.