nerdexam
CompTIA

SY0-301 · Question #340

Joe, a security analyst, asks each employee of an organization to sign a statement saying that they understand how their activities may be monitored. Which of the following BEST describes this…

The correct answer is A. Acceptable use policy C. Privacy policy. A statement informing employees that their activities may be monitored is both an acceptable use policy (which defines permitted use and monitoring) and a privacy policy (which discloses how user activity is observed and recorded).

Security program management and oversight

Question

Joe, a security analyst, asks each employee of an organization to sign a statement saying that they understand how their activities may be monitored. Which of the following BEST describes this statement? (Select TWO).

Options

  • AAcceptable use policy
  • BRisk acceptance policy
  • CPrivacy policy
  • DEmail policy
  • ESecurity policy

How the community answered

(40 responses)
  • A
    88% (35)
  • B
    8% (3)
  • D
    3% (1)
  • E
    3% (1)

Why each option

A statement informing employees that their activities may be monitored is both an acceptable use policy (which defines permitted use and monitoring) and a privacy policy (which discloses how user activity is observed and recorded).

AAcceptable use policyCorrect

An acceptable use policy (AUP) establishes the rules for how organizational resources may be used and explicitly notifies employees of monitoring practices, making it the primary document employees sign to acknowledge these terms.

BRisk acceptance policy

A risk acceptance policy documents the organization's decision to accept a specific identified risk rather than informing employees about activity monitoring.

CPrivacy policyCorrect

A privacy policy discloses to individuals how their personal data and activities may be collected, monitored, or shared; having employees sign this acknowledges their understanding that the organization may observe their actions on company systems.

DEmail policy

An email policy specifically governs the use of organizational email systems and is a subset of broader policies; it does not broadly cover all activity monitoring.

ESecurity policy

A security policy is a high-level governance document defining the organization's overall security objectives and responsibilities; it is not typically what employees sign to acknowledge monitoring of their specific activities.

Concept tested: Acceptable use and privacy policy employee monitoring acknowledgment

Source: https://csrc.nist.gov/glossary/term/acceptable_use_policy

Topics

#acceptable use policy#privacy policy#user monitoring#security policies

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice