Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A company wants every corporate laptop to use the same required screen-lock timeout, disk encryption setting, and local administrator restriction. Which document should define these mandatory settings?

⚠ Common exam trap

Watch out — candidates often confuse a 'standard' (which sets mandatory, measurable requirements) with a 'guideline' (which is optional and advisory), leading candidates to pick A because they think 'required' implies flexibility, when in fact standards are the only document type that enforces specific configuration values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A standard, because it specifies required configuration values

A standard is the correct document type because it mandates specific, measurable configuration values (e.g., screen-lock timeout of 300 seconds, AES-256 disk encryption, removal of local admin rights) that all corporate laptops must enforce. Standards are binding and establish a baseline for security compliance, unlike guidelines which are advisory. This aligns with the company's requirement for mandatory, uniform settings across all devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A guideline, because it offers flexible suggestions for users

    Why it's wrong here

    A guideline provides non-mandatory recommendations and best practices, allowing users or administrators to use their discretion. Because the company requires every laptop to have the same configuration, a guideline lacks the enforcement and specificity needed to ensure uniform compliance. Guidelines are advisory, not binding, so they cannot guarantee the required consistent security baseline.

  • A standard, because it specifies required configuration values

    Why this is correct

    A standard is a formal, mandatory document that defines the exact configuration values (e.g., password policy, OS patch level, encryption settings) that every corporate laptop must adhere to. This creates an enforceable baseline for consistency, compliance, and security audits. Unlike optional recommendations or announcements, a standard is binding and ensures all devices are configured identically.

  • A procedure, because it explains the business reason for security rules

    Why it's wrong here

    A procedure outlines the step-by-step actions or tasks to accomplish something, such as how to install software or handle a security incident. It does not specify the required configuration values themselves, nor does it explain the business rationale—that rationale belongs in a policy. Confusing procedures with configuration standards means overlooking the actual mechanism that mandates the baseline.

  • A memo, because it is the fastest way to communicate changes

    Why it's wrong here

    A memo is a communication vehicle used to quickly announce a change or policy, but it is not a formal control document with long-term authority. It does not provide the legally or technically binding requirements needed for an organization-wide mandatory configuration. Using a memo would fail to establish the durable, enforced baseline that ensures all laptops are secure and auditable.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.