SY0-701 General Security Concepts Practice Question
Exhibit
Endpoint baseline draft: - Full-disk encryption should be enabled on all corporate laptops. - Screen lock should activate after 15 minutes of inactivity. - Users should choose strong passwords. Related documents: Policy: Acceptable Use Policy Standard: none Procedure: Laptop imaging steps Guideline: Suggested hardening tips
Based on the exhibit, which document should be created or updated to make these settings mandatory and measurable?
Endpoint baseline draft: - Full-disk encryption should be enabled on all corporate laptops. - Screen lock should activate after 15 minutes of inactivity. - Users should choose strong passwords.
Related documents: Policy: Acceptable Use Policy Standard: none Procedure: Laptop imaging steps Guideline: Suggested hardening tips
⚠ Common exam trap
Test-takers frequently confuse the role of a policy (broad intent) with a standard (specific, mandatory requirements), leading candidates to choose 'Update the policy' because they assume policies are the most authoritative document for technical settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create or update a standard because it defines mandatory, specific minimum requirements.
A standard defines mandatory, specific minimum requirements that must be met, such as 'full-disk encryption enabled' and 'screen lock after 15 minutes.' Unlike policies (high-level intent) or guidelines (suggestions), a standard provides measurable criteria that can be audited and enforced. Creating or updating a standard makes the endpoint baseline settings mandatory and measurable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the policy because policies are always the most detailed technical documents.
Why it's wrong here
Policies are intentionally written at a high level to communicate management's security objectives and strategic direction, not to specify technical minutiae. Describing them as the 'most detailed technical documents' confuses governance layers: a policy might mandate 'anti-malware shall be used,' but it does not list registry keys or version numbers. That level of enforceable specificity belongs to a standard, which translates policy intent into measurable, mandatory baselines for system configuration and operations.
- ✓
Create or update a standard because it defines mandatory, specific minimum requirements.
Why this is correct
A standard is the correct document type because it operationalizes a policy's high-level intent into explicit, mandatory technical requirements and baseline configurations that can be tested and audited consistently. Unlike a policy, a standard uses normative language (e.g., 'must,' 'shall') to define specific minimum thresholds, such as password length, encryption algorithms, or patch intervals. This makes the standard the authoritative reference for compliance verification and for enforcing uniform security controls across the enterprise.
- ✗
Update the procedure because procedures are the best place for corporate requirements.
Why it's wrong here
Procedures are step-by-step work instructions that describe how to perform a task or implement a control, such as 'how to harden a new server' or 'how to respond to an alert.' They are not the appropriate place for corporate requirements because they assume a standard or policy has already established the 'what' and 'why'; procedures simply provide the 'how.' Placing mandatory requirements in a procedure would bury them in operational instructions, making them difficult to audit and enforce consistently across different teams.
- ✗
Update the guideline because guidelines are the strongest way to enforce compliance.
Why it's wrong here
Guidelines are advisory by nature—they suggest recommended practices or configurations but do not carry a mandatory compliance requirement. Unlike standards, they use tentative language like 'should' or 'consider,' which means they cannot be used as a basis for rejecting a non-compliant implementation or for formal audit findings. Overstating guidelines as the 'strongest way to enforce compliance' inverts the document hierarchy; enforcement requires the binding weight of a standard or policy, not optional guidance.
Go deeper
Related to this question
Learn chapter
Symmetric vs Asymmetric Encryption
Key term
Disk encryption
Disk encryption is the process of converting data on a storage device into a coded form that can only be read with the correct decryption key, protecting it from unauthorized access.
Key term
Hardening
Hardening is the process of securing a computer system or network by reducing its attack surface, disabling unnecessary services, and applying security configurations.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.