SY0-701 Security Program Management and Oversight Practice Question
A security manager wants every corporate laptop to use the same mandatory settings, including disk encryption, a 10-minute screen lock, and removal of local administrator rights. Which document should define these specific requirements?
⚠ Common exam trap
A common mix-up: candidates confuse the broad, principle-based nature of a policy with the specific, mandatory technical requirements of a standard, leading candidates to choose 'Policy' when the question explicitly asks for a document that defines 'specific requirements'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard
A standard defines mandatory, specific technical requirements that must be uniformly applied across all systems, such as enforcing AES-256 disk encryption, a 600-second screen lock timeout, and removal of local administrator rights. Unlike a policy, which is high-level and goal-oriented, a standard provides the precise configuration settings that implement the policy's intent. This aligns with the CompTIA SY0-701 domain of Security Program Management and Oversight, where standards bridge the gap between policy and technical implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy
Why it's wrong here
A policy articulates management's intent and overarching security objectives, such as "all laptops must be secured," but deliberately avoids prescribing exact configuration values. It serves as the foundational governance document, yet it is too high-level to specify technical parameters like screen lock timeouts or encryption ciphers. Relying on policy alone would leave too much room for interpretation, making consistent laptop baselines unachievable. Therefore, while policy mandates the outcome, it cannot dictate the uniform technical implementation the manager requires.
- ✓
Standard
Why this is correct
A standard is the correct document for exact, mandatory configuration requirements. It provides specific, consistent rules such as encryption requirements, lock timers, and privilege restrictions so administrators can implement the same baseline across all laptops. Standards translate policy intent into enforceable technical expectations and make compliance measurable.
- ✗
Guideline
Why it's wrong here
Guidelines offer recommended best practices and are explicitly non-mandatory, meaning they provide flexibility for different environments rather than uniform enforcement. They may suggest sensible options like enabling full-disk encryption, but they do not carry the authority to require every laptop to have the same settings. A security manager who wants identical configurations cannot use guidelines because they lack the binding language and compliance metrics needed for auditability. Thus, guidelines are advisory, not enforceable, and therefore cannot guarantee the desired uniformity.
- ✗
Procedure
Why it's wrong here
A procedure describes the ordered steps to execute a specific action, such as how to install a patch or configure a VPN client, but it does not itself define the mandatory settings. It presumes the target configuration has already been decided elsewhere and focuses on the workflow or command sequence to achieve it. Procedures can vary by task or role yet still reference the same baseline, so they are not the document that establishes the required uniform values. In short, a procedure is an execution guide, not the source of technical requirements.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.