Courseiva
Question 941 of 1,013
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security team is defining the minimum approved configuration for all new Linux web servers. The document must require specific logging settings, approved packages, and disabled services, and administrators must check servers against it during audits. Which governance artifact best fits this need?

⚠ Common exam trap

Many exam-takers confuse 'policy' with 'baseline' because both are governance documents, but a policy is a broad directive (e.g., 'secure all systems') while a baseline provides the specific, auditable technical controls (e.g., 'disable Telnet, enable auditd, use only Apache 2.4') that administrators must enforce.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Baseline, because it defines the minimum approved configuration that systems should meet.

A baseline is the correct governance artifact because it defines the minimum approved configuration that systems must meet, including specific logging settings, approved packages, and disabled services. In the context of Linux web servers, a baseline ensures consistent security posture by providing a measurable standard that administrators can audit against, such as verifying that rsyslog is configured for remote logging, only packages like Apache or Nginx from approved repositories are installed, and services like Telnet or FTP are disabled. This aligns with the requirement for enforcement and auditability, unlike a guideline which is merely advisory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Guideline, because it suggests recommended settings without requiring enforcement.

    Why it's wrong here

    Guidelines are non-mandatory recommendations that suggest best practices for configuration, but they lack the enforceable language and measurable thresholds required for compliance checks. Because the security team needs a documented minimum configuration that administrators will audit against, a guideline carries no 'shall' or 'must' requirements. A baseline, in contrast, specifies the exact settings that systems must meet, making guidelines useful as a reference but not as the auditable standard.

  • Baseline, because it defines the minimum approved configuration that systems should meet.

    Why this is correct

    A baseline is the correct artifact when an organization wants a documented, measurable starting configuration for systems. It captures the approved minimum settings, such as required services, logging, and packages, and supports consistent builds and compliance checks. Because the question describes a configuration that administrators will audit against, a baseline fits better than a guideline or a general policy.

  • Policy, because it is the high-level statement of intent for the organization.

    Why it's wrong here

    A policy is a pervasive, high-level statement of management intent that defines the organization's security goals and responsibilities, but it deliberately avoids technical detail such as registry values, service states, or required patches. While a policy may mandate that systems be securely configured, it is too abstract to serve as the minimum approved configuration itself. That precise technical threshold is the role of a baseline, which translates policy into concrete, testable requirements.

  • Procedure, because it explains the exact steps to install and configure each server.

    Why it's wrong here

    A procedure is a set of step-by-step instructions that describe how to install, configure, or manage a server, focusing on the sequence of actions for personnel to follow. It is process-oriented and does not define the end-state configuration that systems must satisfy for compliance. Auditors compare actual system settings against a baseline standard, not against a procedure, so a procedure cannot replace a baseline as the minimum approved configuration.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.