SY0-701 Security Program Management and Oversight Practice Question
A policy states that sensitive data must be encrypted, but it does not say which encryption strength to use. The security architect wants a document that lists the exact approved encryption settings for systems to follow. What document is needed?
⚠ Common exam trap
Watch out — candidates often confuse a standard with a guideline: candidates often pick 'guideline' because both documents provide technical details, but a standard is mandatory and prescriptive, while a guideline is advisory and flexible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A standard, because it specifies the required technical values and configurations.
A standard is the correct document because it mandates specific, measurable technical requirements—such as exact encryption algorithms (e.g., AES-256), key lengths, and cipher modes (e.g., GCM)—that systems must follow to comply with the policy. Unlike a policy, which states a goal (e.g., 'encrypt sensitive data'), a standard provides the enforceable configuration baseline that the security architect needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A procedure, because it explains the step-by-step order for handling every file.
Why it's wrong here
A procedure is a defined sequence of actions for completing a particular operation, such as using a tool to encrypt a file. It does not establish the required cryptographic strength, algorithm, or configuration values that the policy demands. Without a standard specifying those technical parameters, the encryption requirement remains unenforceable and non-measurable across systems.
- ✓
A standard, because it specifies the required technical values and configurations.
Why this is correct
A standard is the right document when the organization needs exact, mandatory technical settings such as approved encryption strength or configuration values. The policy provides the high-level requirement, while the standard translates that requirement into measurable controls that systems and auditors can follow consistently.
- ✗
A guideline, because it gives suggestions that teams may choose to adopt.
Why it's wrong here
Guidelines are inherently advisory and non-binding, offering recommended practices rather than obligatory controls. The policy uses the mandatory word 'must,' which signals a compliance requirement that optional suggestions cannot satisfy. Only a standard can impose the rigid, enforceable encryption strength and configuration parameters needed to meet the policy's intent.
- ✗
A memo, because it is the fastest way to tell teams about a new requirement.
Why it's wrong here
A memo is a transient communication tool used to announce changes or remind staff, not a formal governance document. It lacks the hierarchy, review, and authority of a standard, and it is not designed to persist as an auditable control. Relying on a memo would leave the encryption requirement without a fixed technical baseline, making consistent enforcement impossible.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Advanced Encryption Standard
Advanced Encryption Standard (AES) is a widely used symmetric encryption algorithm that protects electronic data by converting readable information into a scrambled format that can only be unscrambled with the correct secret key.
Key term
AES
AES is a fast and secure encryption standard used worldwide to protect sensitive data by scrambling it so only authorized parties can read it.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.