What Type of Security Control Is an Acceptable Use Policy (AUP)?

Which of the following control types is AUP an example of?

  1. Physical
  2. Managerial Source Reference Answer
  3. Technical
  4. Operational

Community Votes

B
66%
D
34%

66% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to classify controls by recognizing that policy-driven documentation belongs to the Managerial category, even though it indirectly guides daily operations.

An Acceptable Use Policy (AUP) is classified as a Managerial control because it establishes organizational governance and user guidelines rather than implementing technical enforcement or physical barriers. While some candidates confuse it with Operational controls due to its day-to-day behavioral impact, CompTIA SY0-701 consistently categorizes formal policy documents under the Managerial domain.

Candidates frequently select Operational (D) because AUP directly dictates daily user behavior and workflows; however, Operational controls specifically refer to personnel executing routine procedures (like backup checks or shift logs), whereas the AUP itself is a governing policy document, making it Managerial.

Community Discussion (18 comments)

Examplary 👍 9 Selected: B
Direct from Dion Training's Udemy course: Managerial Controls - Aka administrative controls. Involve the strategic planning and governance side of security. Ensures that the org’s security strategies align with its business goals and its risk tolerance. Risk assessments Security policies Training programs Incident response strategies Operational Controls - Procedures and measures designed to protect data on a day-to-day basis and are mainly governed by internal processes and human actions. Backup procedures Account reviews User awareness training programs AUP = Acceptable Use Policy. Security policies = Managerial Controls.
saba263 👍 6 Selected: B
An AUP (Acceptable Use Policy) is an example of a Managerial control. Explanation: An AUP outlines the guidelines and expectations for how users should interact with an organization's systems, which falls under the category of management controls as it defines policies and procedures rather than physical security measures or technical implementations.
nawtitoo 👍 1 Selected: D
An Acceptable Use Policy (AUP) outlines rules and guidelines for acceptable behavior and proper usage of an organization's resources, such as computers, networks, and internet services. It is considered an operational control because it defines day-to-day practices, procedures, and standards that help manage and secure the organization's operations.
AndyK2 👍 1 Selected: B
Both Claude and GPT suggest >>> Managerial
gingergroot 👍 2 Selected: B
From the CompTIA SYO-701 Study Guide - "Managerial controls are administrative in function and documented in security policies. Operational controls are implemented by people who perform the day-to-day operations to comply with an organization's overall security plan."
Fourgehan 👍 1 Selected: B
An Acceptable Use Policy (AUP) is a document or agreement that defines acceptable and unacceptable behaviors when using an organization's resources, such as computers, networks, and data. It is a managerial control because it involves creating policies, guidelines, and standards to manage and govern the behavior of users within an organization. It does not implement any technical enforcement but instead provides the framework and rules.
3b6be6b 👍 1 Selected: D
Its and operational control according to Comptia.
saba263 👍 2
An AUP (Acceptable Use Policy) is an example of a Managerial control. Explanation: An AUP outlines the guidelines and expectations for how users should interact with an organization's systems, which falls under the category of management controls as it defines policies and procedures rather than physical security measures or technical implementations.
User92 👍 3 Selected: D
In fact, Comptia asks the same practical question and uses AUP as the example of operational controls.
Chrisssy6111 👍 3 Selected: D
D. Operational. Comptia gives this same practice question and uses AUP as an specific example of operational controls.
RIDA_007 👍 2
Managerial controls are tend to be directive such as policies, hence I am gowing with B. Remember that operational controls are driven by people like security guards, more physical in nature.
myazureexams 👍 3 Selected: B
Many of you are quoting GPT responses. However, you have to offer the correct prompt. As follows: Operational control or managerial control? The choices are managerial or operational. I understand it is a type of administrative control, but that is not one of the choices. Please explain the best answer: GPT Answer: Based on the given choices, an Acceptable Use Policy (AUP) would be considered a managerial control. This is because it establishes guidelines and policies that guide the organization's operations, which aligns more with the concept of managerial control. I am definitely going with Managerial, which was my first answer before consulting GPT. I've also studied for over a year in-depth.
PAWarriors 👍 3 Selected: D
D. Operational: Operational controls are procedures and policies that dictate how users should behave and how processes are carried out to ensure security. The AUP falls under this category as it defines acceptable and unacceptable behavior for users, making it an operational control.
Hayder81 👍 1
B. Managerial control.
Zobo411 👍 1 Selected: D
GPTTTTTTTTTTTTTTTT
850bc48 👍 4
Chat GPT: The correct answer is D. Operational. An Acceptable Use Policy (AUP) is an example of an operational control. It defines the appropriate use of resources, such as networks, systems, and data, by users within an organization. AUPs are administrative in nature and help to manage behavior and actions within an organization's environment, making them part of operational controls. A. Physical controls are designed to protect the physical infrastructure, like locks, badges, or surveillance cameras. B. Managerial controls focus on the oversight and management of security policies, such as risk assessments and audits. C. Technical controls (also known as logical controls) include things like firewalls, encryption, and access control systems, which rely on technology to enforce security.
Cee007 👍 1 Selected: B
B. Managerial An AUP is a set of guidelines or rules established by management to dictate acceptable and unacceptable use of organizational resources, such as computers and networks. It is a managerial control designed to ensure that users adhere to security policies and practices.
Syl0 👍 1
AUP - Acceptable Use Policies

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Security Control Classifications

In the CompTIA Security+ SY0-701 framework, security controls are primarily categorized into three domains: Managerial (Administrative), Technical (Logical), and Physical. Each serves a distinct purpose in risk mitigation.

Why an AUP is a Managerial Control

An Acceptable Use Policy (AUP) is a formal document that outlines rules, expectations, and consequences for how employees and users interact with organizational resources. Because it focuses on governance, compliance, and risk management rather than direct technical implementation, it falls squarely under Managerial controls. As noted in the Sybex SY0-701 study guide and Dion Training materials, managerial controls are administrative in nature and documented through policies, standards, and procedures.

The Operational vs. Managerial Confusion

The community debate stems from overlapping terminology in broader frameworks like NIST SP 800-53, where "operational" controls include both managerial and operational families. In CompTIA’s exam context, however, Operational controls typically refer to day-to-day human-executed processes (e.g., security awareness training delivery, incident response execution, routine log reviews) that enforce the policies. The AUP itself is the policy, not the execution. Selecting Operational confuses the rulebook with the gameplay. As several top-voted community explanations highlight, CompTIA explicitly classifies policy documents under Managerial, reserving Operational for procedural actions carried out by staff.

Eliminating Other Options

  • Physical controls involve tangible measures like locks, biometric scanners, surveillance cameras, and environmental safeguards. An AUP has no physical component.
  • Technical controls are implemented via hardware or software (e.g., firewalls, encryption, MFA, ACLs). An AUP cannot technically enforce usage; it relies on managerial oversight and disciplinary action.
  • Operational controls manage the ongoing human aspects of security operations. While an AUP influences operations, it remains a governance artifact, not an operational procedure itself.

Conclusion

For the SY0-701 exam, always map policies, standards, and guidelines to Managerial controls. This distinction ensures you avoid the common trap of over-indexing on real-world workflow impact rather than the control’s formal classification.

Official Reference

  • CompTIA Security+ SY0-701 Official Study Guide (Sybex)
  • NIST Special Publication 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
  • CompTIA Security+ SY0-701 Exam Objectives - Section 1.3: Risk Management

Exam Strategy

When classifying security controls, immediately identify the artifact's primary function: if it is a written policy, guideline, or compliance requirement, choose Managerial; if it involves hardware/software enforcement, choose Technical; if it involves tangible barriers or personnel guarding assets, choose Physical. Reserve Operational for questions describing routine human-led procedures or workflow executions, and remember that CompTIA treats formal policy documents strictly under the Managerial umbrella.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide