Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager publishes a document that tells help desk staff exactly how to verify identity, reset an admin password, record the ticket number, and close out the request during a maintenance window. What type of governance artifact is this?

⚠ Common exam trap

Watch out — candidates often confuse a procedure with a policy or standard, where candidates often pick 'policy' because they think any security document is a policy, but the detailed step-by-step nature uniquely identifies a procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Procedure

A procedure is a step-by-step, ordered list of tasks required to perform a specific operational activity. The document describes exactly how to verify identity, reset an admin password, record the ticket number, and close out the request, which matches the definition of a procedure in governance frameworks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why it's wrong here

    A policy is a high-level directive that defines the organization's security goals, principles, and responsibilities, such as 'all access must be authorized.' It explains why a task must be done but not how to execute it, leaving room for implementation decisions. The security manager's document specifically tells help desk staff what steps to follow, which is operational detail a policy is not designed to provide.

  • Standard

    Why it's wrong here

    A standard is a mandatory rule or baseline that specifies what must be done, such as requiring a minimum password length or specific encryption protocols. It sets concrete thresholds and controls, but it does not describe the ordered workflow of actions needed to complete a help desk task. The document in question gives a sequence of steps, which is beyond the scope of a standard and is instead the role of a procedure.

  • Procedure

    Why this is correct

    A procedure is the correct choice because it provides a detailed, step-by-step set of actions that must be performed in order to complete a task reliably and consistently. The security manager's document tells help desk staff exactly how to handle an issue, ensuring that every employee follows the same sequence and meets security and quality expectations. Procedures are essential for routine operational tasks, such as verifying identity before resetting a password, because they reduce ambiguity and support auditing and training.

  • Guideline

    Why it's wrong here

    A guideline is advisory and provides recommended, non-mandatory ways to accomplish a goal, allowing staff to exercise judgment or adapt to context. If the security manager's document were a guideline, help desk staff would be free to deviate from the steps, creating inconsistent and potentially insecure outcomes. Since the document appears to define a fixed sequence of required actions, it is not a guideline but a mandated procedure.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.