Courseiva
Security Program Management and OversighthardMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Document ID: BAS-014
Title: Windows 11 Laptop Minimum Configuration
Scope: All corporate laptops
Requirements: Full-disk encryption enabled; screen lock after 10 minutes; approved EDR installed; USB mass storage blocked; local administrator rights removed
Approval: Security manager and endpoint engineering lead
Review cycle: annually or after major OS changes

Based on the exhibit, which governance artifact is being described?

⚠ Common exam trap

Watch out — candidates often confuse a standard with a baseline, but a standard is a broader mandatory requirement (e.g., 'use encryption') while a baseline specifies the exact minimum acceptable configuration (e.g., 'use AES-256 with a key length of 256 bits').

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Baseline, because it defines the approved minimum configuration that systems must meet.

The exhibit describes a baseline because it specifies the approved minimum configuration settings that systems must meet, such as requiring AES-256 encryption, disabling weak protocols like SSL and TLS 1.0, and enforcing a minimum password length of 14 characters. These are mandatory security thresholds, not broad intent, step-by-step instructions, or optional standards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy, because it states broad organizational intent without requiring specific settings.

    Why it's wrong here

    A policy is a high-level directive that communicates management intent, objectives, and overall security principles, but it does not prescribe specific technical values or configuration settings. The exhibit enumerates explicit, mandatory settings for every laptop, which is far too granular and implementation-specific for a policy. Policies define the 'why' and 'what' at a broad organizational level; the 'how' with concrete settings belongs to lower-level artifacts like baselines or standards.

  • Standard, because it defines mandatory requirements but does not describe a step-by-step process.

    Why it's wrong here

    Although a standard can impose mandatory requirements and even specify particular configurations, it does not inherently frame those requirements as a 'minimum configuration' or security floor. The exhibit is explicitly labeled as a minimum configuration, which is the defining role of a baseline—a reference point for consistent hardening, drift detection, and compliance auditing. Standards typically address a broader set of compliance criteria, whereas a baseline zeroes in on the exact approved minimum state that systems must meet.

  • Procedure, because it explains the exact sequence an administrator should follow to secure the device.

    Why it's wrong here

    A procedure provides an ordered sequence of steps or actions that an administrator must follow to complete a task, including how and when to execute those steps. The exhibit is a declarative list of configuration settings and values, not a set of instructions or a workflow. It defines the end state (the minimum security configuration) rather than the process to achieve that state; a procedure might be used to implement the baseline, but the artifact itself is clearly the baseline, not the procedure.

  • Baseline, because it defines the approved minimum configuration that systems must meet.

    Why this is correct

    The exhibit is labeled as a minimum configuration and lists required settings that establish the approved security floor for all laptops. That is the classic purpose of a baseline. It provides a reference point for configuration consistency and drift detection, and it is often approved by security and technical owners together. The annual review cycle also fits a controlled baseline update process.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.