220-1102 · Question #159
A technician receives a call from a user who is on vacation. The user provides the necessary credentials and asks the technician to log in to the user's account and read a critical email that the…
The correct answer is A. acceptable use policy. An Acceptable Use Policy (AUP) defines the rules governing how users and IT staff may interact with organizational systems, accounts, and data. Even when a user voluntarily provides their own credentials, a technician logging into that account and reading private emails…
Question
A technician receives a call from a user who is on vacation. The user provides the necessary credentials and asks the technician to log in to the user's account and read a critical email that the user has been expecting. The technician refuses because this is a violation of the:
Options
- Aacceptable use policy.
- Bregulatory compliance requirements.
- Cnon-disclosure agreement.
- Dincident response procedures.
How the community answered
(25 responses)- A84% (21)
- B4% (1)
- C4% (1)
- D8% (2)
Explanation
An Acceptable Use Policy (AUP) defines the rules governing how users and IT staff may interact with organizational systems, accounts, and data. Even when a user voluntarily provides their own credentials, a technician logging into that account and reading private emails violates the AUP because it involves unauthorized access to personal communications on behalf of another person. The AUP exists to protect both users and the organization. The other options don't fit: regulatory compliance (B) governs legal obligations, an NDA (C) covers confidentiality of shared information, and incident response procedures (D) are for handling security events - none of these directly prohibit the action described.
Topics
Community Discussion
No community discussion yet for this question.