SY0-701 Security Program Management and Oversight Practice Question
A security team wants every company laptop to have the same screen-lock timeout, disk encryption setting, and local firewall configuration. Which type of document should define these mandatory settings?
⚠ Common exam trap
Test-takers frequently confuse a standard with a guideline, as many candidates assume any security document is advisory, but standards are explicitly mandatory and enforceable, unlike guidelines which are optional recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A standard, because it specifies mandatory technical requirements.
A standard is the correct document type because it defines mandatory technical requirements that must be uniformly enforced across all company laptops. In this scenario, the screen-lock timeout, disk encryption setting (e.g., BitLocker or FileVault), and local firewall configuration (e.g., Windows Defender Firewall with Advanced Security) are non-negotiable controls that must be applied identically to every device to meet security policy. Standards are binding and often reference specific configuration baselines, such as CIS Benchmarks or NIST SP 800-53, ensuring consistent implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A guideline, because employees can decide whether to follow it.
Why it's wrong here
A guideline is fundamentally advisory, offering recommended practices that employees may choose to follow at their own discretion. Because the security team requires every laptop to have identical mandatory settings, a guideline cannot compel consistent implementation of a screen-lock timeout, full-disk encryption, or host-based firewall rules. It lacks the normative, enforceable language of a standard, so it is the wrong tool for achieving uniform, auditable compliance.
- ✓
A standard, because it specifies mandatory technical requirements.
Why this is correct
A standard is the correct document for mandatory, measurable security settings such as screen-lock timeouts, encryption, and firewall configuration. Standards turn policy intent into specific requirements that can be checked and enforced across devices, which helps keep configurations consistent and easier to audit.
- ✗
A risk register, because it tracks all security vulnerabilities on laptops.
Why it's wrong here
A risk register is a living document used to catalog identified vulnerabilities, threat events, likelihood, impact scores, and the status of risk treatment decisions. It does not define what baseline security configuration must be applied to laptops, nor does it specify technical controls such as encryption algorithms or lockout timeouts. Its purpose is to track and manage risks over time, not to serve as a source of mandatory device hardening requirements.
- ✗
A business impact analysis, because it identifies the most important laptop functions.
Why it's wrong here
A business impact analysis (BIA) evaluates critical business functions, their dependencies, maximum tolerable downtime, and recovery priorities after an outage or disaster. It does not identify the specific technical settings needed to harden endpoint devices; instead, it focuses on operational and financial consequences rather than configuration management. Because the goal is to standardize laptop security configurations, the BIA is inappropriate, as it measures business impact, not device security baselines.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Windows Defender Firewall
Windows Defender Firewall is a built-in security feature in Microsoft Windows that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.