nerdexam
(ISC)2

SSCP · Question #1203

A security policy is a rigid set of rules that must be followed explicitly in order to be effective.

The correct answer is B. False. A security policy provides a framework and guidelines for security, but it is not necessarily a rigid set of rules that must be followed explicitly without any room for interpretation or adaptation.

Submitted by femi9· Apr 18, 2026Security Concepts and Practices

Question

A security policy is a rigid set of rules that must be followed explicitly in order to be effective.

Options

  • ATrue
  • BFalse

How the community answered

(53 responses)
  • A
    13% (7)
  • B
    87% (46)

Why each option

A security policy provides a framework and guidelines for security, but it is not necessarily a rigid set of rules that must be followed explicitly without any room for interpretation or adaptation.

ATrue

This statement is false because while security policies define critical boundaries and requirements, they often need to be flexible enough to accommodate evolving technologies, business needs, and threat landscapes, rather than being an entirely inflexible set of explicit rules.

BFalseCorrect

Security policies are foundational documents that define an organization's security posture and requirements, but they are not always rigid and allow for interpretation and adaptation to different situations and technologies. While policies set boundaries, procedures and standards provide the explicit, detailed steps.

Concept tested: Characteristics of security policies

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/management#policies-standards-and-guidelines

Topics

#Security Policy#Policy Characteristics#Policy Effectiveness

Community Discussion

No community discussion yet for this question.

Full SSCP Practice