Courseiva
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

Exhibit

Endpoint baseline draft:
- Full-disk encryption should be enabled on all corporate laptops.
- Screen lock should activate after 15 minutes of inactivity.
- Users should choose strong passwords.

Related documents:
Policy: Acceptable Use Policy
Standard: none
Procedure: Laptop imaging steps
Guideline: Suggested hardening tips

Based on the exhibit, which document should be created or updated to make these settings mandatory and measurable?

Endpoint baseline draft: - Full-disk encryption should be enabled on all corporate laptops. - Screen lock should activate after 15 minutes of inactivity. - Users should choose strong passwords.

Related documents: Policy: Acceptable Use Policy Standard: none Procedure: Laptop imaging steps Guideline: Suggested hardening tips

⚠ Common exam trap

Test-takers frequently confuse the role of a policy (broad intent) with a standard (specific, mandatory requirements), leading candidates to choose 'Update the policy' because they assume policies are the most authoritative document for technical settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create or update a standard because it defines mandatory, specific minimum requirements.

A standard defines mandatory, specific minimum requirements that must be met, such as 'full-disk encryption enabled' and 'screen lock after 15 minutes.' Unlike policies (high-level intent) or guidelines (suggestions), a standard provides measurable criteria that can be audited and enforced. Creating or updating a standard makes the endpoint baseline settings mandatory and measurable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Update the policy because policies are always the most detailed technical documents.

    Why it's wrong here

    Policies are intentionally written at a high level to communicate management's security objectives and strategic direction, not to specify technical minutiae. Describing them as the 'most detailed technical documents' confuses governance layers: a policy might mandate 'anti-malware shall be used,' but it does not list registry keys or version numbers. That level of enforceable specificity belongs to a standard, which translates policy intent into measurable, mandatory baselines for system configuration and operations.

  • Create or update a standard because it defines mandatory, specific minimum requirements.

    Why this is correct

    A standard is the correct document type because it operationalizes a policy's high-level intent into explicit, mandatory technical requirements and baseline configurations that can be tested and audited consistently. Unlike a policy, a standard uses normative language (e.g., 'must,' 'shall') to define specific minimum thresholds, such as password length, encryption algorithms, or patch intervals. This makes the standard the authoritative reference for compliance verification and for enforcing uniform security controls across the enterprise.

  • Update the procedure because procedures are the best place for corporate requirements.

    Why it's wrong here

    Procedures are step-by-step work instructions that describe how to perform a task or implement a control, such as 'how to harden a new server' or 'how to respond to an alert.' They are not the appropriate place for corporate requirements because they assume a standard or policy has already established the 'what' and 'why'; procedures simply provide the 'how.' Placing mandatory requirements in a procedure would bury them in operational instructions, making them difficult to audit and enforce consistently across different teams.

  • Update the guideline because guidelines are the strongest way to enforce compliance.

    Why it's wrong here

    Guidelines are advisory by nature—they suggest recommended practices or configurations but do not carry a mandatory compliance requirement. Unlike standards, they use tentative language like 'should' or 'consider,' which means they cannot be used as a basis for rejecting a non-compliant implementation or for formal audit findings. Overstating guidelines as the 'strongest way to enforce compliance' inverts the document hierarchy; enforcement requires the binding weight of a standard or policy, not optional guidance.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.