SY0-701 Security Program Management and Oversight Practice Question
A company wants every corporate laptop to use the same required screen-lock timeout, disk encryption setting, and local administrator restriction. Which document should define these mandatory settings?
⚠ Common exam trap
Watch out — candidates often confuse a 'standard' (which sets mandatory, measurable requirements) with a 'guideline' (which is optional and advisory), leading candidates to pick A because they think 'required' implies flexibility, when in fact standards are the only document type that enforces specific configuration values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A standard, because it specifies required configuration values
A standard is the correct document type because it mandates specific, measurable configuration values (e.g., screen-lock timeout of 300 seconds, AES-256 disk encryption, removal of local admin rights) that all corporate laptops must enforce. Standards are binding and establish a baseline for security compliance, unlike guidelines which are advisory. This aligns with the company's requirement for mandatory, uniform settings across all devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A guideline, because it offers flexible suggestions for users
Why it's wrong here
A guideline provides non-mandatory recommendations and best practices, allowing users or administrators to use their discretion. Because the company requires every laptop to have the same configuration, a guideline lacks the enforcement and specificity needed to ensure uniform compliance. Guidelines are advisory, not binding, so they cannot guarantee the required consistent security baseline.
- ✓
A standard, because it specifies required configuration values
Why this is correct
A standard is a formal, mandatory document that defines the exact configuration values (e.g., password policy, OS patch level, encryption settings) that every corporate laptop must adhere to. This creates an enforceable baseline for consistency, compliance, and security audits. Unlike optional recommendations or announcements, a standard is binding and ensures all devices are configured identically.
- ✗
A procedure, because it explains the business reason for security rules
Why it's wrong here
A procedure outlines the step-by-step actions or tasks to accomplish something, such as how to install software or handle a security incident. It does not specify the required configuration values themselves, nor does it explain the business rationale—that rationale belongs in a policy. Confusing procedures with configuration standards means overlooking the actual mechanism that mandates the baseline.
- ✗
A memo, because it is the fastest way to communicate changes
Why it's wrong here
A memo is a communication vehicle used to quickly announce a change or policy, but it is not a formal control document with long-term authority. It does not provide the legally or technically binding requirements needed for an organization-wide mandatory configuration. Using a memo would fail to establish the durable, enforced baseline that ensures all laptops are secure and auditable.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Compliance and Regulatory Frameworks
Key term
AES
AES is a fast and secure encryption standard used worldwide to protect sensitive data by scrambling it so only authorized parties can read it.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.