SY0-301 · Question #340
Joe, a security analyst, asks each employee of an organization to sign a statement saying that they understand how their activities may be monitored. Which of the following BEST describes this…
The correct answer is A. Acceptable use policy C. Privacy policy. A statement informing employees that their activities may be monitored is both an acceptable use policy (which defines permitted use and monitoring) and a privacy policy (which discloses how user activity is observed and recorded).
Question
Joe, a security analyst, asks each employee of an organization to sign a statement saying that they understand how their activities may be monitored. Which of the following BEST describes this statement? (Select TWO).
Options
- AAcceptable use policy
- BRisk acceptance policy
- CPrivacy policy
- DEmail policy
- ESecurity policy
How the community answered
(40 responses)- A88% (35)
- B8% (3)
- D3% (1)
- E3% (1)
Why each option
A statement informing employees that their activities may be monitored is both an acceptable use policy (which defines permitted use and monitoring) and a privacy policy (which discloses how user activity is observed and recorded).
An acceptable use policy (AUP) establishes the rules for how organizational resources may be used and explicitly notifies employees of monitoring practices, making it the primary document employees sign to acknowledge these terms.
A risk acceptance policy documents the organization's decision to accept a specific identified risk rather than informing employees about activity monitoring.
A privacy policy discloses to individuals how their personal data and activities may be collected, monitored, or shared; having employees sign this acknowledges their understanding that the organization may observe their actions on company systems.
An email policy specifically governs the use of organizational email systems and is a subset of broader policies; it does not broadly cover all activity monitoring.
A security policy is a high-level governance document defining the organization's overall security objectives and responsibilities; it is not typically what employees sign to acknowledge monitoring of their specific activities.
Concept tested: Acceptable use and privacy policy employee monitoring acknowledgment
Source: https://csrc.nist.gov/glossary/term/acceptable_use_policy
Topics
Community Discussion
No community discussion yet for this question.