220-1102 Question 751
Single answerAcceptable use policy (AUP)A company issues laptops to employees and requires them to sign an acceptable use policy (AUP). During a routine review, a technician discovers an employee installed a peer-to-peer file-sharing application and has been using company bandwidth to download personal media. The employee says this is acceptable because the laptop was assigned exclusively to them and no malware has been detected. What should the technician do FIRST?
- A
Remove the application and document the incident according to company policy
- B
Ignore the activity because no security incident has occurred
- C
Reimage the laptop immediately without notifying anyone
- D
Allow the activity if the employee agrees to run weekly antivirus scans
Show answer and explanation
Correct answer: A
Explanation
Acceptable use policies are administrative controls that define how users may and may not use company devices, networks, software, and internet access. In this scenario, the issue is not just malware risk; it is unauthorized use of organizational resources and likely violation of software, security, and bandwidth policies. A technician should follow the organization's documented procedure: stop or remediate the prohibited activity as authorized, document the finding, and escalate or report through the proper chain, such as a supervisor, security team, or HR, depending on policy. This approach is consistent with common security best practices emphasizing policy enforcement, least privilege, change control, and incident documentation. CompTIA A+ Core 2 objectives commonly expect candidates to distinguish between technical fixes and policy-based responses, especially for AUP, onboarding/offboarding, and end-user security compliance.
- A. Correct.
Correct. An AUP defines permitted and prohibited use of company systems, including misuse of company bandwidth, unauthorized software installation, and personal file sharing. The technician should follow organizational procedure by addressing the violation, documenting it, and escalating or notifying the appropriate party as required by policy. This is the most appropriate first response because it aligns with administrative controls and preserves an audit trail.
- B. Incorrect.
Incorrect. The absence of detected malware does not make the behavior acceptable. AUP violations are policy issues even when they have not yet caused a confirmed security event. Ignoring the activity fails to enforce company rules and could expose the organization to legal, licensing, bandwidth, and security risks.
- C. Incorrect.
Incorrect. Reimaging might remove the software, but doing so immediately without following policy or documenting the violation is not the best first step. It could also destroy evidence or interfere with any required management or HR process. In most organizations, incident handling and policy enforcement require documentation and proper notification.
- D. Incorrect.
Incorrect. Weekly antivirus scans do not address the actual problem, which is unauthorized and prohibited use under the AUP. This option reflects the misconception that technical mitigation can replace policy compliance. Even if the system is clean, unauthorized software and personal file-sharing activity may still violate company rules.