SY0-701 General Security Concepts Practice Question
A security manager wants to require that all company laptops use at least a 14-character password and lock after 10 minutes of inactivity. Which document should define these mandatory settings?
⚠ Common exam trap
Many exam-takers confuse a policy (broad intent) with a standard (specific, mandatory technical values), leading candidates to choose Option A because they think all security rules are policies, when in fact standards define the enforceable numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard, because it defines specific required technical values the company must follow.
A standard is the document type that defines mandatory, specific technical requirements, such as a minimum 14-character password length and a 10-minute inactivity lock. Policies are high-level statements of intent, while standards provide the enforceable, measurable parameters that implement that intent. In this scenario, the security manager needs a binding baseline, which is precisely the role of a standard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it is the broad statement of security intent only.
Why it's wrong here
A policy is a high-level statement of management intent and security objectives; it establishes the organization's overall security direction but deliberately avoids implementation details. For example, a policy might say 'all laptops must be configured securely,' but it does not specify that the password must be exactly 14 characters or that the screen locks after 5 minutes of inactivity. Defining those concrete numeric thresholds is beyond a policy's scope, so it would be insufficient as the sole document to enforce the specific technical values the security manager needs.
- ✓
Standard, because it defines specific required technical values the company must follow.
Why this is correct
A standard is the right document when the organization wants specific, mandatory technical requirements. Password length and screen-lock timeout are measurable settings, so they belong in a standard rather than a general policy. Standards make implementation consistent across systems and help administrators configure devices to the same baseline.
- ✗
Guideline, because it gives optional recommendations for device security.
Why it's wrong here
A guideline is a set of recommended, non-mandatory best practices that offer flexibility and are intended to be adapted to different situations. While a guideline might suggest 'consider enabling screen lock after a short idle period,' it cannot be enforced as a strict baseline because it explicitly permits deviation. The security manager's requirement is a mandatory, measurable threshold (specific password length and timeout), which contradicts the inherently discretionary nature of a guideline; thus, it cannot be the correct choice for establishing required configurable values.
- ✗
Memo, because it is the normal formal document for security baselines.
Why it's wrong here
A memo is an informal communication tool used to announce changes, remind staff of policies, or convey temporary instructions; it is not designed to serve as a formal, durable security standard. Even if the memo contains the exact password length and timeout values, it lacks the authoritative governance status and review/revision process that a standard or policy document carries. In a real organization, administrators would not treat a memo as the baseline reference for configuration enforcement, and it would quickly become stale or be overlooked, so it is not the proper vehicle for a security baseline.
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.