Courseiva
mediumMatchingObjective-mapped

SSCP Practice Question: Match each security policy type to its purpose.

Match each security policy type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines proper use of resources

Requirements for password strength

Categorizes data sensitivity

Procedures for handling breaches

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Acceptable Use Policy: Defines acceptable behaviors and proper use of organizational IT resources.

The correct matches are: Acceptable Use Policy (acceptable use), Data Classification Policy (data categorization), Password Policy (password rules), Incident Response Policy (incident handling). Common confusions: mixing up policy scopes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Acceptable Use Policy: Defines acceptable behaviors and proper use of organizational IT resources.

    Why this is correct

    This is the correct purpose of an Acceptable Use Policy.

  • Data Classification Policy: Specifies how data is categorized by sensitivity to apply appropriate controls.

    Why this is correct

    This is the correct purpose of a Data Classification Policy.

  • Password Policy: Establishes rules for password creation, complexity, and management.

    Why this is correct

    This is the correct purpose of a Password Policy.

  • Incident Response Policy: Outlines procedures for detecting, responding to, and recovering from security incidents.

    Why this is correct

    This is the correct purpose of an Incident Response Policy.

  • Acceptable Use Policy: Outlines procedures for incident detection and response.

    Why it's wrong here

    Incorrect — this describes an Incident Response Policy, not an Acceptable Use Policy.

  • Data Classification Policy: Defines rules for password complexity and rotation.

    Why it's wrong here

    Incorrect — this describes a Password Policy, not a Data Classification Policy.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.