SY0-701 Security Program Management and Oversight Practice Question
After several password-reset incidents, the security team wants one document that sets mandatory minimum controls for privileged accounts and another that tells the help desk the exact steps to verify identity and reset access. Which two document types should they use? Select two.
⚠ Common exam trap
Test-takers frequently confuse a policy (high-level intent) with a standard (mandatory minimums), and a guideline (optional) with a procedure (step-by-step), leading candidates to pick A and D instead of B and C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard, because it defines the mandatory minimum requirements that everyone must follow.
A standard defines mandatory minimum requirements that must be followed, such as password length, complexity, and MFA enforcement for privileged accounts. This ensures consistent security controls across the organization without ambiguity, unlike a policy which is high-level intent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it explains the organization's overall security intent in broad terms.
Why it's wrong here
A policy is a high-level document that conveys management's overall security intent and principles (e.g., 'protect the confidentiality of credentials'). It establishes the 'why' but does not specify the mandatory control details or exact operational steps needed to perform a password reset securely. While policy is foundational, it lacks the measurable, enforceable requirements (like MFA or minimum password length) and the step-by-step actions that this scenario demands, so it cannot serve as the requested standard and procedure.
- ✓
Standard, because it defines the mandatory minimum requirements that everyone must follow.
Why this is correct
A standard is the right document for mandatory baseline requirements, such as minimum password length, MFA requirements, or privileged account rules. It converts policy intent into specific, measurable requirements that can be enforced consistently across the organization.
- ✓
Procedure, because it gives the exact step-by-step actions for help desk staff.
Why this is correct
A procedure is the correct choice for detailed execution instructions. It tells staff precisely how to verify identity, open the ticket, perform the reset, and record the action. That consistency is especially important for sensitive tasks like account recovery.
- ✗
Guideline, because it provides recommended practices that staff may ignore if needed.
Why it's wrong here
A guideline offers advisory, recommended practices that are never truly mandatory; staff could reasonably choose to ignore it without violating formal security requirements. For a high-risk support function like password resets, relying on a guideline would allow inconsistent identity verification, ticket handling, and reset execution, potentially reintroducing the very incidents the organization wants to prevent. The question specifically asks for one document that mandates minimum requirements and another that gives exact steps, so a guideline, being optional, is not the right choice for either.
- ✗
Baseline, because it is mainly used as a casual reference document for analysts.
Why it's wrong here
A baseline can define a known-good configuration state, but it is not the best answer for the two requested document types. The scenario specifically calls for one mandatory requirement document and one step-by-step operational document.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.