Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager wants one document that states employees must protect company laptops and another that defines exact required settings such as disk encryption and a 10-minute screen lock. Which two document types are the best fit? Select two.

⚠ Common exam trap

It's easy for candidates to confuse 'policy' with 'guideline' or 'procedure'—candidates often pick 'guideline' for the technical settings because they think it's a recommendation, but standards are the only document type that mandates exact technical configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Policy

A policy is a high-level statement of management intent, such as requiring employees to protect company laptops. A standard defines mandatory, specific technical settings, like requiring disk encryption (e.g., AES-256) and a 10-minute screen lock timeout. Together, they provide the overarching directive (policy) and the enforceable configuration baseline (standard).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why this is correct

    A policy is a formal, board-approved statement of management intent that establishes mandatory, high-level expectations for security behavior. It explains the "what" and "why"—for example, employees must protect laptops and company data—without dictating specific technical implementations. As the foundational governance document, it sets the legal and compliance boundary for all lower-level documentation.

  • Standard

    Why this is correct

    A standard operationalizes a policy by defining exact, mandatory technical settings—such as requiring AES-256 encryption for laptops and a 15-minute idle timeout for screens. It provides a measurable, consistent baseline that can be verified and enforced by technical teams. While it is also required, it presupposes the existence of a policy that states the overarching rule it supports.

  • Guideline

    Why it's wrong here

    A guideline offers recommended best practices and is explicitly advisory and flexible, leaving room for judgment based on situational needs. Since it is not mandatory, personnel may choose to follow alternative approaches if they meet the underlying security objectives. Therefore, a guideline cannot be the document that states employees must do something, because it lacks any enforcement authority.

  • Procedure

    Why it's wrong here

    A procedure explains the exact step-by-step actions needed to perform a task, such as how to encrypt a laptop or how to report a lost device. It is operational and task-sequenced, but it assumes the mandatory baseline already exists in a higher-level document. A procedure tells people how to comply, not what the mandatory requirement is, so it cannot stand alone as the baseline.

  • Exception

    Why it's wrong here

    An exception is a formally recorded approval to deviate from an established policy or standard for a specified reason and time period. It comes into play only after a baseline has been defined and an employee cannot meet it, and it must be approved by authorized management. Making an exception the primary document would eliminate the baseline itself, collapsing the governance framework.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.