What Type of Security Control Is an Acceptable Use Policy (AUP)?
Which of the following control types is AUP an example of?
Community Votes
66% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to classify controls by recognizing that policy-driven documentation belongs to the Managerial category, even though it indirectly guides daily operations.
An Acceptable Use Policy (AUP) is classified as a Managerial control because it establishes organizational governance and user guidelines rather than implementing technical enforcement or physical barriers. While some candidates confuse it with Operational controls due to its day-to-day behavioral impact, CompTIA SY0-701 consistently categorizes formal policy documents under the Managerial domain.
Candidates frequently select Operational (D) because AUP directly dictates daily user behavior and workflows; however, Operational controls specifically refer to personnel executing routine procedures (like backup checks or shift logs), whereas the AUP itself is a governing policy document, making it Managerial.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Security Control Classifications
In the CompTIA Security+ SY0-701 framework, security controls are primarily categorized into three domains: Managerial (Administrative), Technical (Logical), and Physical. Each serves a distinct purpose in risk mitigation.Why an AUP is a Managerial Control
An Acceptable Use Policy (AUP) is a formal document that outlines rules, expectations, and consequences for how employees and users interact with organizational resources. Because it focuses on governance, compliance, and risk management rather than direct technical implementation, it falls squarely under Managerial controls. As noted in the Sybex SY0-701 study guide and Dion Training materials, managerial controls are administrative in nature and documented through policies, standards, and procedures.The Operational vs. Managerial Confusion
The community debate stems from overlapping terminology in broader frameworks like NIST SP 800-53, where "operational" controls include both managerial and operational families. In CompTIA’s exam context, however, Operational controls typically refer to day-to-day human-executed processes (e.g., security awareness training delivery, incident response execution, routine log reviews) that enforce the policies. The AUP itself is the policy, not the execution. Selecting Operational confuses the rulebook with the gameplay. As several top-voted community explanations highlight, CompTIA explicitly classifies policy documents under Managerial, reserving Operational for procedural actions carried out by staff.Eliminating Other Options
- Physical controls involve tangible measures like locks, biometric scanners, surveillance cameras, and environmental safeguards. An AUP has no physical component.
- Technical controls are implemented via hardware or software (e.g., firewalls, encryption, MFA, ACLs). An AUP cannot technically enforce usage; it relies on managerial oversight and disciplinary action.
- Operational controls manage the ongoing human aspects of security operations. While an AUP influences operations, it remains a governance artifact, not an operational procedure itself.
Conclusion
For the SY0-701 exam, always map policies, standards, and guidelines to Managerial controls. This distinction ensures you avoid the common trap of over-indexing on real-world workflow impact rather than the control’s formal classification.Official Reference
- CompTIA Security+ SY0-701 Official Study Guide (Sybex)
- NIST Special Publication 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
- CompTIA Security+ SY0-701 Exam Objectives - Section 1.3: Risk Management
Exam Strategy
When classifying security controls, immediately identify the artifact's primary function: if it is a written policy, guideline, or compliance requirement, choose Managerial; if it involves hardware/software enforcement, choose Technical; if it involves tangible barriers or personnel guarding assets, choose Physical. Reserve Operational for questions describing routine human-led procedures or workflow executions, and remember that CompTIA treats formal policy documents strictly under the Managerial umbrella.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →