Courseiva

SSCP Security Operations and Administration Practice Question

A company wants to ensure that employees understand the proper use of corporate email and internet. Which policy should they implement?

⚠ Common exam trap

The SSCP exam often tests the distinction between policies that are broad (like AUP) versus those that are narrowly focused on specific technical controls (like password or remote access), leading candidates to confuse a general usage guideline with a security control policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acceptable Use Policy

An Acceptable Use Policy (AUP) defines the rules and guidelines for using corporate IT resources, including email and internet. It specifies permitted and prohibited activities, such as personal browsing, sending sensitive data, or accessing inappropriate content, ensuring employees understand their responsibilities. This policy directly addresses the company's goal of educating employees on proper usage, unlike other policies that focus on data classification, remote connectivity, or authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Handling Policy

    Why it's wrong here

    A Data Handling Policy classifies information and prescribes storage, transmission, retention and destruction rules per classification level. It does not instruct employees on acceptable email or internet behaviour. An Acceptable Use Policy is the correct instrument, defining permitted use of those corporate resources.

  • ✗

    Remote Access Policy

    Why it's wrong here

    A Remote Access Policy governs how external connections into corporate systems are authenticated and permitted, covering VPN, dial-in and endpoint requirements. It says nothing about acceptable email and internet usage. An Acceptable Use Policy is the correct instrument for defining permitted employee behaviour on email and web resources.

  • ✓

    Acceptable Use Policy

    Why this is correct

    An Acceptable Use Policy defines permitted employee behaviour for corporate email and internet resources, directly addressing the stated need. It specifies what staff may and may not do with these assets, unlike password or access policies that govern credentials.

  • ✗

    Password Policy

    Why it's wrong here

    A Password Policy specifies credential composition, rotation, reuse and lockout rules for authentication. It does not address how employees may use email or browse the internet. Acceptable Use Policy is the correct instrument, since it defines permitted and prohibited behaviour for those specific resources.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.