Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager wants every corporate laptop to use the same mandatory settings, including disk encryption, a 10-minute screen lock, and removal of local administrator rights. Which document should define these specific requirements?

⚠ Common exam trap

A common mix-up: candidates confuse the broad, principle-based nature of a policy with the specific, mandatory technical requirements of a standard, leading candidates to choose 'Policy' when the question explicitly asks for a document that defines 'specific requirements'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Standard

A standard defines mandatory, specific technical requirements that must be uniformly applied across all systems, such as enforcing AES-256 disk encryption, a 600-second screen lock timeout, and removal of local administrator rights. Unlike a policy, which is high-level and goal-oriented, a standard provides the precise configuration settings that implement the policy's intent. This aligns with the CompTIA SY0-701 domain of Security Program Management and Oversight, where standards bridge the gap between policy and technical implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why it's wrong here

    A policy articulates management's intent and overarching security objectives, such as "all laptops must be secured," but deliberately avoids prescribing exact configuration values. It serves as the foundational governance document, yet it is too high-level to specify technical parameters like screen lock timeouts or encryption ciphers. Relying on policy alone would leave too much room for interpretation, making consistent laptop baselines unachievable. Therefore, while policy mandates the outcome, it cannot dictate the uniform technical implementation the manager requires.

  • Standard

    Why this is correct

    A standard is the correct document for exact, mandatory configuration requirements. It provides specific, consistent rules such as encryption requirements, lock timers, and privilege restrictions so administrators can implement the same baseline across all laptops. Standards translate policy intent into enforceable technical expectations and make compliance measurable.

  • Guideline

    Why it's wrong here

    Guidelines offer recommended best practices and are explicitly non-mandatory, meaning they provide flexibility for different environments rather than uniform enforcement. They may suggest sensible options like enabling full-disk encryption, but they do not carry the authority to require every laptop to have the same settings. A security manager who wants identical configurations cannot use guidelines because they lack the binding language and compliance metrics needed for auditability. Thus, guidelines are advisory, not enforceable, and therefore cannot guarantee the desired uniformity.

  • Procedure

    Why it's wrong here

    A procedure describes the ordered steps to execute a specific action, such as how to install a patch or configure a VPN client, but it does not itself define the mandatory settings. It presumes the target configuration has already been decided elsewhere and focuses on the workflow or command sequence to achieve it. Procedures can vary by task or role yet still reference the same baseline, so they are not the document that establishes the required uniform values. In short, a procedure is an execution guide, not the source of technical requirements.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.