Courseiva
Question 51 of 1,013
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

During onboarding, a manager wants a document that explains how to request access to a shared drive, who approves it, and what the help desk must do after approval. Which document type is MOST appropriate?

⚠ Common exam trap

Test-takers frequently confuse a procedure with a policy or standard, where candidates pick 'policy' because it sounds authoritative, but fail to recognize that procedures are the only document type that provides ordered steps for a specific workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Procedure, because it provides the ordered steps for requesting and fulfilling access.

A procedure is the correct document type because it specifies the exact ordered steps for requesting access to a shared drive, the approval authority, and the help desk's post-approval actions. Unlike a policy, which states high-level security principles, a procedure provides the operational workflow needed for onboarding tasks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Guideline, because it describes optional best practices for access requests.

    Why it's wrong here

    Guidelines provide recommended practices and are intentionally flexible, allowing staff to adapt them to different situations. However, the scenario demands a prescriptive, ordered procedure for how access requests are submitted, reviewed, and fulfilled. A guideline does not enforce a mandatory sequence of actions or specify roles and approvals, so it would not guarantee the consistency and auditability the manager needs.

  • Procedure, because it provides the ordered steps for requesting and fulfilling access.

    Why this is correct

    A procedure is the best document for describing the sequence of actions, approvals, and responsibilities involved in a recurring task. In this case, it would tell users how to submit the request, who reviews it, and what the help desk does after approval. Procedures improve consistency and reduce errors in operational workflows.

  • Policy, because it names the general security principle without implementation detail.

    Why it's wrong here

    A policy articulates the organization's overall security stance, such as 'access must be granted based on least privilege,' but intentionally omits implementation details. It does not explain the practical workflow of who fills out a form, who approves it, or how the help desk processes the request. Since the user is onboarding and wants to know the exact steps, a policy is too abstract to serve as an instructional guide.

  • Standard, because it should define every case-specific approval path in the organization.

    Why it's wrong here

    A standard defines mandatory requirements or configuration baselines, but it does not describe the sequential workflow for a specific operational task. Even if a standard dictates that all access requests require manager approval, it would not lay out the step-by-step process from submission to fulfillment. The claim that a standard should enumerate every case-specific approval path confuses standards with procedures, which are designed to codify repeatable actions and responsibilities.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.