SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Document ID: BAS-014 Title: Windows 11 Laptop Minimum Configuration Scope: All corporate laptops Requirements: Full-disk encryption enabled; screen lock after 10 minutes; approved EDR installed; USB mass storage blocked; local administrator rights removed Approval: Security manager and endpoint engineering lead Review cycle: annually or after major OS changes
Based on the exhibit, which governance artifact is being described?
⚠ Common exam trap
Watch out — candidates often confuse a standard with a baseline, but a standard is a broader mandatory requirement (e.g., 'use encryption') while a baseline specifies the exact minimum acceptable configuration (e.g., 'use AES-256 with a key length of 256 bits').
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baseline, because it defines the approved minimum configuration that systems must meet.
The exhibit describes a baseline because it specifies the approved minimum configuration settings that systems must meet, such as requiring AES-256 encryption, disabling weak protocols like SSL and TLS 1.0, and enforcing a minimum password length of 14 characters. These are mandatory security thresholds, not broad intent, step-by-step instructions, or optional standards.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it states broad organizational intent without requiring specific settings.
Why it's wrong here
A policy is a high-level directive that communicates management intent, objectives, and overall security principles, but it does not prescribe specific technical values or configuration settings. The exhibit enumerates explicit, mandatory settings for every laptop, which is far too granular and implementation-specific for a policy. Policies define the 'why' and 'what' at a broad organizational level; the 'how' with concrete settings belongs to lower-level artifacts like baselines or standards.
- ✗
Standard, because it defines mandatory requirements but does not describe a step-by-step process.
Why it's wrong here
Although a standard can impose mandatory requirements and even specify particular configurations, it does not inherently frame those requirements as a 'minimum configuration' or security floor. The exhibit is explicitly labeled as a minimum configuration, which is the defining role of a baseline—a reference point for consistent hardening, drift detection, and compliance auditing. Standards typically address a broader set of compliance criteria, whereas a baseline zeroes in on the exact approved minimum state that systems must meet.
- ✗
Procedure, because it explains the exact sequence an administrator should follow to secure the device.
Why it's wrong here
A procedure provides an ordered sequence of steps or actions that an administrator must follow to complete a task, including how and when to execute those steps. The exhibit is a declarative list of configuration settings and values, not a set of instructions or a workflow. It defines the end state (the minimum security configuration) rather than the process to achieve that state; a procedure might be used to implement the baseline, but the artifact itself is clearly the baseline, not the procedure.
- ✓
Baseline, because it defines the approved minimum configuration that systems must meet.
Why this is correct
The exhibit is labeled as a minimum configuration and lists required settings that establish the approved security floor for all laptops. That is the classic purpose of a baseline. It provides a reference point for configuration consistency and drift detection, and it is often approved by security and technical owners together. The annual review cycle also fits a controlled baseline update process.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
AES
AES is a fast and secure encryption standard used worldwide to protect sensitive data by scrambling it so only authorized parties can read it.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.