Question 936 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Current governance set: - Policy: Security changes must be approved and recorded. - Standard: All change requests must use the enterprise ITSM platform. - Procedure: Step-by-step instructions show screenshots from the old ITSM tool. - Guideline: Teams may add helpful notes, but the content is optional. Change note: - The company replaced the ITSM platform last week. - Approval workflow, evidence requirements, and retention rules did not change.
Based on the exhibit, which document should be updated first to reflect the new ticketing platform while keeping approval requirements unchanged?
⚠ Common exam trap
Watch out — candidates often confuse 'procedure' with 'standard' or 'policy,' assuming any tool change requires updating the highest-level document, when in fact only the detailed implementation steps (procedure) need revision if the rules and requirements remain unchanged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure, because the step-by-step instructions and screenshots are now outdated.
The procedure document contains the step-by-step instructions, including screenshots and specific commands for the old ticketing platform. Since the new platform changes the user interface and workflow steps, the procedure must be updated first to ensure technicians can follow accurate instructions. Policies and standards define high-level rules and approval requirements, which remain unchanged, so they do not need immediate revision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because every tool change requires rewriting the corporate mandate.
Why it's wrong here
Policy is a high-level governance document that defines the organization's security objectives and the programs that support them, not the step-by-step mechanics of each tool. A change to an ITSM interface does not alter the underlying security requirement or the policy that mandates it, so rewriting policy first would be excessive and slow. Furthermore, policy revisions typically require change advisory board review and formal publication, which would unnecessarily delay the immediate operational correction that users need.
- ✗
Standard, because the approval workflow and evidence rules are still the same.
Why it's wrong here
Standards specify the mandatory rules and control requirements, such as the approval workflow and evidence submission formats, and these remain valid after the interface change. The standard describes 'what' must be done, not 'how' to navigate the new tool, so it does not need to be revised for a GUI update. Updating the standard first would miss the actual problem: the procedure, which contains the concrete steps to be performed, is what has become inconsistent with the current platform.
- ✓
Procedure, because the step-by-step instructions and screenshots are now outdated.
Why this is correct
Procedures contain the operational steps people follow to complete a task. Since the workflow and approval rules remain the same but the tool interface changed, the step-by-step guide should be updated first. That keeps the control intent intact while preventing user confusion and process errors.
- ✗
Guideline, because optional content should always be revised before mandatory content.
Why it's wrong here
Guidelines are discretionary recommendations that describe a preferred approach, not enforceable steps, so they rarely contain the tool-specific screenshots that have gone stale. The assertion that optional content should always be revised before mandatory content is logically flawed because priority should be given to the document with the greatest impact on day-to-day execution. Since the procedure contains the mandatory instructions that users follow to complete the task, outdated guidelines are a minor concern compared to the risk of process errors from a broken procedure.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.