SY0-701 Security Program Management and Oversight Practice Question
An IT manager wants a document that defines the mandatory minimum requirements for all company laptops, including full-disk encryption, password length, and screen-lock timing. The help desk also needs a separate document that shows exactly how to enroll a laptop in management software. Which document type should contain the mandatory laptop requirements?
⚠ Common exam trap
A common mix-up: candidates confuse a standard with a policy, where candidates mistakenly think a policy can contain technical specifics, but CompTIA tests that a policy is always high-level and a standard provides the mandatory technical details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard, because it defines the required technical settings that must be followed.
A standard defines mandatory, specific technical requirements that must be uniformly applied, such as full-disk encryption (e.g., AES-256), minimum password length (e.g., 14 characters), and screen-lock timeout (e.g., 5 minutes). Unlike a policy, which provides high-level direction, a standard enforces precise configuration baselines that all laptops must meet, ensuring compliance and security consistency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it gives broad direction without technical detail.
Why it's wrong here
A policy is a high-level management statement that articulates the organization's security goals and intent, such as 'endpoints must be configured securely.' It deliberately avoids prescriptive technical detail, leaving the specific numerical values or configuration choices undefined. Because the IT manager needs enforceable, technical benchmarks like specific encryption algorithms or exact password lengths, a policy alone would be too abstract to satisfy that requirement.
- ✓
Standard, because it defines the required technical settings that must be followed.
Why this is correct
A standard is the correct document type for mandatory, measurable technical requirements. In this case, the organization needs exact minimum settings for encryption, password length, and screen-lock timing, which are all enforceable specifications. The procedure for enrolling devices would be a separate document that explains how to carry out the requirement, but the baseline technical requirements belong in the standard.
- ✗
Procedure, because it gives step-by-step instructions for completing a task.
Why it's wrong here
A procedure is an operational document that provides step-by-step instructions for completing a particular task, for example, the enrollment process for a new laptop or the steps to reset a forgotten password. It assumes that the underlying security baselines already exist and focuses on the workflow, not on defining required settings. The scenario asks for the document that establishes the mandatory technical parameters themselves, so a procedure would be the wrong type; instead, a procedure would reference the standard for those parameters.
- ✗
Guideline, because it offers flexible recommendations for administrators.
Why it's wrong here
A guideline is a non-mandatory, advisory document that suggests recommended practices and permits discretion based on risk tolerance or environmental context. Guidelines use language like 'should' or 'consider' and do not impose enforceable requirements on all assets. Because the IT manager needs uniform, mandatory settings (e.g., a specific screen-lock timeout or minimum password length) that every device must follow, a guideline's flexibility directly conflicts with the need for strict compliance.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Advanced Encryption Standard
Advanced Encryption Standard (AES) is a widely used symmetric encryption algorithm that protects electronic data by converting readable information into a scrambled format that can only be unscrambled with the correct secret key.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.