Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security team wants every company laptop to have the same screen-lock timeout, disk encryption setting, and local firewall configuration. Which type of document should define these mandatory settings?

⚠ Common exam trap

Test-takers frequently confuse a standard with a guideline, as many candidates assume any security document is advisory, but standards are explicitly mandatory and enforceable, unlike guidelines which are optional recommendations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A standard, because it specifies mandatory technical requirements.

A standard is the correct document type because it defines mandatory technical requirements that must be uniformly enforced across all company laptops. In this scenario, the screen-lock timeout, disk encryption setting (e.g., BitLocker or FileVault), and local firewall configuration (e.g., Windows Defender Firewall with Advanced Security) are non-negotiable controls that must be applied identically to every device to meet security policy. Standards are binding and often reference specific configuration baselines, such as CIS Benchmarks or NIST SP 800-53, ensuring consistent implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A guideline, because employees can decide whether to follow it.

    Why it's wrong here

    A guideline is fundamentally advisory, offering recommended practices that employees may choose to follow at their own discretion. Because the security team requires every laptop to have identical mandatory settings, a guideline cannot compel consistent implementation of a screen-lock timeout, full-disk encryption, or host-based firewall rules. It lacks the normative, enforceable language of a standard, so it is the wrong tool for achieving uniform, auditable compliance.

  • A standard, because it specifies mandatory technical requirements.

    Why this is correct

    A standard is the correct document for mandatory, measurable security settings such as screen-lock timeouts, encryption, and firewall configuration. Standards turn policy intent into specific requirements that can be checked and enforced across devices, which helps keep configurations consistent and easier to audit.

  • A risk register, because it tracks all security vulnerabilities on laptops.

    Why it's wrong here

    A risk register is a living document used to catalog identified vulnerabilities, threat events, likelihood, impact scores, and the status of risk treatment decisions. It does not define what baseline security configuration must be applied to laptops, nor does it specify technical controls such as encryption algorithms or lockout timeouts. Its purpose is to track and manage risks over time, not to serve as a source of mandatory device hardening requirements.

  • A business impact analysis, because it identifies the most important laptop functions.

    Why it's wrong here

    A business impact analysis (BIA) evaluates critical business functions, their dependencies, maximum tolerable downtime, and recovery priorities after an outage or disaster. It does not identify the specific technical settings needed to harden endpoint devices; instead, it focuses on operational and financial consequences rather than configuration management. Because the goal is to standardize laptop security configurations, the BIA is inappropriate, as it measures business impact, not device security baselines.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.