Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

An IT manager wants a document that defines the mandatory minimum requirements for all company laptops, including full-disk encryption, password length, and screen-lock timing. The help desk also needs a separate document that shows exactly how to enroll a laptop in management software. Which document type should contain the mandatory laptop requirements?

⚠ Common exam trap

A common mix-up: candidates confuse a standard with a policy, where candidates mistakenly think a policy can contain technical specifics, but CompTIA tests that a policy is always high-level and a standard provides the mandatory technical details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Standard, because it defines the required technical settings that must be followed.

A standard defines mandatory, specific technical requirements that must be uniformly applied, such as full-disk encryption (e.g., AES-256), minimum password length (e.g., 14 characters), and screen-lock timeout (e.g., 5 minutes). Unlike a policy, which provides high-level direction, a standard enforces precise configuration baselines that all laptops must meet, ensuring compliance and security consistency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy, because it gives broad direction without technical detail.

    Why it's wrong here

    A policy is a high-level management statement that articulates the organization's security goals and intent, such as 'endpoints must be configured securely.' It deliberately avoids prescriptive technical detail, leaving the specific numerical values or configuration choices undefined. Because the IT manager needs enforceable, technical benchmarks like specific encryption algorithms or exact password lengths, a policy alone would be too abstract to satisfy that requirement.

  • Standard, because it defines the required technical settings that must be followed.

    Why this is correct

    A standard is the correct document type for mandatory, measurable technical requirements. In this case, the organization needs exact minimum settings for encryption, password length, and screen-lock timing, which are all enforceable specifications. The procedure for enrolling devices would be a separate document that explains how to carry out the requirement, but the baseline technical requirements belong in the standard.

  • Procedure, because it gives step-by-step instructions for completing a task.

    Why it's wrong here

    A procedure is an operational document that provides step-by-step instructions for completing a particular task, for example, the enrollment process for a new laptop or the steps to reset a forgotten password. It assumes that the underlying security baselines already exist and focuses on the workflow, not on defining required settings. The scenario asks for the document that establishes the mandatory technical parameters themselves, so a procedure would be the wrong type; instead, a procedure would reference the standard for those parameters.

  • Guideline, because it offers flexible recommendations for administrators.

    Why it's wrong here

    A guideline is a non-mandatory, advisory document that suggests recommended practices and permits discretion based on risk tolerance or environmental context. Guidelines use language like 'should' or 'consider' and do not impose enforceable requirements on all assets. Because the IT manager needs uniform, mandatory settings (e.g., a specific screen-lock timeout or minimum password length) that every device must follow, a guideline's flexibility directly conflicts with the need for strict compliance.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.