Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A policy states that sensitive data must be encrypted, but it does not say which encryption strength to use. The security architect wants a document that lists the exact approved encryption settings for systems to follow. What document is needed?

⚠ Common exam trap

Watch out — candidates often confuse a standard with a guideline: candidates often pick 'guideline' because both documents provide technical details, but a standard is mandatory and prescriptive, while a guideline is advisory and flexible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A standard, because it specifies the required technical values and configurations.

A standard is the correct document because it mandates specific, measurable technical requirements—such as exact encryption algorithms (e.g., AES-256), key lengths, and cipher modes (e.g., GCM)—that systems must follow to comply with the policy. Unlike a policy, which states a goal (e.g., 'encrypt sensitive data'), a standard provides the enforceable configuration baseline that the security architect needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A procedure, because it explains the step-by-step order for handling every file.

    Why it's wrong here

    A procedure is a defined sequence of actions for completing a particular operation, such as using a tool to encrypt a file. It does not establish the required cryptographic strength, algorithm, or configuration values that the policy demands. Without a standard specifying those technical parameters, the encryption requirement remains unenforceable and non-measurable across systems.

  • A standard, because it specifies the required technical values and configurations.

    Why this is correct

    A standard is the right document when the organization needs exact, mandatory technical settings such as approved encryption strength or configuration values. The policy provides the high-level requirement, while the standard translates that requirement into measurable controls that systems and auditors can follow consistently.

  • A guideline, because it gives suggestions that teams may choose to adopt.

    Why it's wrong here

    Guidelines are inherently advisory and non-binding, offering recommended practices rather than obligatory controls. The policy uses the mandatory word 'must,' which signals a compliance requirement that optional suggestions cannot satisfy. Only a standard can impose the rigid, enforceable encryption strength and configuration parameters needed to meet the policy's intent.

  • A memo, because it is the fastest way to tell teams about a new requirement.

    Why it's wrong here

    A memo is a transient communication tool used to announce changes or remind staff, not a formal governance document. It lacks the hierarchy, review, and authority of a standard, and it is not designed to persist as an auditable control. Relying on a memo would leave the encryption requirement without a fixed technical baseline, making consistent enforcement impossible.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.