Courseiva
Security Operations and AdministrationeasyMultiple ChoiceObjective-mapped

SSCP Security Operations and Administration Practice Question

A security administrator is drafting an acceptable use policy (AUP). Which of the following should be included to address the use of personal devices for work purposes?

⚠ Common exam trap

A common mix-up: candidates confuse the AUP with broader security policies like incident response or data backup, but the AUP specifically governs user behavior and access controls, not operational procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Requirements for password complexity and multifactor authentication

An acceptable use policy (AUP) for personal devices (BYOD) must include authentication requirements like password complexity and multifactor authentication to ensure that only authorized users can access corporate resources from potentially untrusted endpoints. This directly addresses the security risk of unauthorized access via personal devices, which is a primary concern in BYOD environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Procedures for data backup and recovery

    Why it's wrong here

    Backup procedures are typically part of a backup policy or operational procedure, not the AUP.

  • Requirements for password complexity and multifactor authentication

    Why this is correct

    The AUP should define security requirements for personal devices, such as password complexity and MFA, to ensure they meet organizational security standards.

  • Guidelines for responding to security incidents

    Why it's wrong here

    Incident response procedures are documented in an incident response plan, not in the AUP.

  • A list of approved social media platforms

    Why it's wrong here

    Social media platforms may be covered in a separate policy or section, but the core of AUP for personal devices is about permissible use and security controls.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.