nerdexam
CompTIA

SY0-301 · Question #197

In which of the following categories would creating a corporate privacy policy, drafting acceptable use policies, and group based access control be classified?

The correct answer is B. Best practice. Best practices are widely accepted, industry-recognized methods and procedures that organizations adopt to improve security posture. Creating privacy policies, acceptable use policies (AUPs), and implementing group-based access control are all examples of documented best…

Security program management and oversight

Question

In which of the following categories would creating a corporate privacy policy, drafting acceptable use policies, and group based access control be classified?

Options

  • ASecurity control frameworks
  • BBest practice
  • CAccess control methodologies
  • DCompliance activity

How the community answered

(36 responses)
  • A
    17% (6)
  • B
    72% (26)
  • C
    8% (3)
  • D
    3% (1)

Explanation

Best practices are widely accepted, industry-recognized methods and procedures that organizations adopt to improve security posture. Creating privacy policies, acceptable use policies (AUPs), and implementing group-based access control are all examples of documented best practices for organizational security governance. Security control frameworks (A) refer to structured sets of controls like NIST, ISO 27001, or CIS Controls. Access control methodologies (C) refer specifically to models like DAC, MAC, or RBAC. Compliance activities (D) are actions taken to satisfy specific regulatory or legal requirements - these policies may support compliance but the act of creating them is best classified as a best practice.

Topics

#security policies#acceptable use policy#best practices#policy classification

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice