Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy

A financial institution is implementing a new customer data platform. To comply with various industry regulations (e.g., PCI DSS, GDPR) and internal security standards, the development team is required to follow strict guidelines for data handling, access control, and encryption. These guidelines are formally documented and communicated across all relevant departments. Which security concept do these guidelines primarily represent?

  1. ASecurity Reporting
  2. BSecurity Audits
  3. CSecurity Metrics
  4. DSecurity Policies
Show answer & explanation

Correct answer: D. Security Policies

Formal, documented guidelines for data handling, access control, and encryption, especially when driven by regulations and internal standards, are core components of security policies.

Why the other options are wrong

  • A. Security reporting involves communicating security status and incidents, which is different from defining the rules of engagement.
  • B. Security audits are formal examinations to verify compliance with policies and standards, not the policies themselves.
  • C. Security metrics are measurements of security effectiveness, not the guidelines themselves.

Security Policies

Formal, documented statements that define the rules, requirements, and responsibilities for protecting an organization's information assets.

  • Provide a framework for security controls.
  • Driven by legal, regulatory, and business requirements.
  • Communicated to all relevant personnel.

Memory trick: Policies are the rules written down, to keep the company's data sound.

More Security Concepts questions