Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A help desk team is writing a procedure for resetting MFA after a user loses a phone. Which two details belong in the procedure rather than in the policy? Select two.

⚠ Common exam trap

Many candidates confuse policy (broad rules and goals) with procedure (specific, actionable steps), leading candidates to select high-level statements like 'all employees must use MFA' instead of the detailed verification and tool-specific steps that actually belong in a procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The exact step-by-step verification process the technician must follow

A procedure must contain the exact step-by-step verification process the technician follows to confirm the user's identity before resetting MFA. This operational detail ensures consistency and security, whereas a policy would only state the high-level requirement (e.g., 'verify identity'). Without precise steps, technicians might skip critical checks, leading to unauthorized MFA resets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The exact step-by-step verification process the technician must follow

    Why this is correct

    The exact step-by-step verification process is the core of any standard operating procedure. For MFA resets, this includes verifying the user's identity via a secondary channel (e.g., manager approval, knowledge-based verification) and enumerating the sequence of admin console actions. This specificity ensures that any technician performs the reset identically, minimizing risk of unauthorized changes and creating an auditable trail.

  • The specific screen clicks or tool used to reset the MFA device

    Why this is correct

    The specific screen clicks or tool used to reset the MFA device is procedural detail because it tells the technician the exact interface elements and paths, e.g., Active Directory Users and Computers > user properties > Multi-Factor Authentication > Reset. This granularity differentiates a procedure from a policy, as it translates the requirement into concrete, repeatable actions that can be tested and verified.

  • A statement that all employees must use MFA to access company systems

    Why it's wrong here

    A statement that all employees must use MFA is a policy requirement that defines an organizational rule, not a procedure. Procedures describe how to accomplish a task, whereas policies define what is required and why. Forcing this into a help desk procedure would produce non-actionable text that fails to guide the technician through the reset steps, and it would be redundant with broader security policies.

  • A general goal of protecting accounts from unauthorized access

    Why it's wrong here

    A general goal of protecting accounts from unauthorized access is the business purpose behind MFA, not the implementation steps. Including it in a procedure would mix governance intent with operational actions, blurring the line between strategy and execution. Procedures should assume the goal is already established and focus only on the how, ensuring clarity and reducing cognitive load for technicians.

  • A broad rule that users should protect company credentials

    Why it's wrong here

    A broad rule that users should protect company credentials is a high-level security guideline or policy, not a help desk procedure. It lacks the procedural specificity such as the exact verification workflow, the admin tool to use, and the order of actions. Including it in a reset procedure would be an editorial statement that does not instruct the technician on anything concrete, and it belongs in an employee security awareness policy instead.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.