SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Service desk draft: - Verify caller using employee ID and manager callback - Reset password in the IAM portal - Record ticket number and recovery method - Ask user to confirm no sensitive applications are open Management request: "Turn this draft into the document analysts must follow exactly when a user is locked out."
Based on the exhibit, which document type should the service desk use for the locked-account workflow?
⚠ Common exam trap
Test-takers frequently confuse a procedure with a policy or standard, as candidates often think 'rules for account access' (policy) or 'password requirements' (standard) apply to the workflow, but only a procedure provides the exact sequential steps needed for operational tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure, because it lists the exact steps analysts must follow in sequence.
A procedure document is the correct choice because it provides a step-by-step sequence of actions that service desk analysts must follow to unlock an account. The locked-account workflow requires precise, ordered steps (e.g., verifying identity, checking lockout status, resetting the account) to ensure consistency and security, which aligns with the definition of a procedure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it states broad rules for account access.
Why it's wrong here
A policy is a mandatory, high-level statement of management intent that establishes the organization's overall position on account access, such as 'all users shall be provisioned with least privilege.' It deliberately avoids granular, task-level detail so that it remains durable and principles-based. The exhibit, however, provides a sequential workflow for identity verification and password reset, which is operational guidance rather than a broad rule, so 'policy' misclassifies the document.
- ✗
Standard, because it defines the minimum password requirements for all users.
Why it's wrong here
A standard translates a policy into measurable, mandatory baseline requirements—such as a minimum 12-character password, or enforcing MFA—that can be audited and enforced consistently. It does not prescribe the exact order of service-desk actions, and two teams meeting the same standard could still use entirely different workflows. The exhibit contains a specific, step-by-step operational sequence (verify identity → reset password → record ticket → confirm), which goes far beyond a baseline requirement, so 'standard' is not the correct type.
- ✓
Procedure, because it lists the exact steps analysts must follow in sequence.
Why this is correct
A procedure is the correct document when management wants analysts to perform a task exactly the same way every time. The exhibit contains sequential steps for identity verification, password reset, ticket recording, and user confirmation. That is operational guidance, not a broad policy statement or an optional guideline.
- ✗
Guideline, because it gives flexible suggestions for handling locked accounts.
Why it's wrong here
A guideline is an optional, flexible recommendation that offers general best practices or alternate approaches, allowing the analyst to use judgment based on the situation. In contrast, the exhibit uses directive language and a fixed order—identity verification before password reset, then ticket recording and user confirmation—which implies that staff must not deviate. Because procedures mandate identical step-by-step execution while guidelines permit discretion, labeling this a guideline would contradict the document's prescriptive nature.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Procedure
A documented set of step-by-step instructions for performing a specific task or handling a particular situation in an IT environment.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.