Courseiva
Question 1,146 of 1,013

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

1. All company laptops must use full-disk encryption, automatic screen locking after 10 minutes, and the approved EDR agent.
2. To replace a lost MFA token, the help desk must verify identity, disable the old token, and re-enroll the user before access is restored.
3. Users should avoid storing confidential files on removable media unless there is a documented business need.
4. The engineering team may use one unsupported browser plug-in on two workstations for 30 days while a redesign is completed.
5. Remote access is allowed only through the approved VPN with MFA.

Match each excerpt from a small enterprise security program to the correct governance artifact.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Standard

Procedure

Guideline

Exception

Policy

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Policy: All employees must use multi-factor authentication

Policy defines mandatory rules; Procedure gives step-by-step instructions; Standard specifies technical requirements; Guideline offers best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy: All employees must use multi-factor authentication

    Why this is correct

    A policy is a formal, mandatory statement of management intent, and 'must' makes this requirement non-negotiable for all employees. It establishes an organization-wide rule without prescribing the underlying mechanics, such as which MFA app or hardware token to use—that level of detail would live in a standard or procedure. Therefore, classifying this as Policy is correct because it sets an enforceable expectation.

  • Procedure: To reset a password, follow steps 1-5

    Why this is correct

    A procedure is a detailed, ordered sequence of actions for completing a specific task, and the phrase 'follow steps 1-5' signals exactly that. Unlike a policy (a rule) or a standard (a technical requirement), this excerpt instructs the user how to perform a password reset step by step. The presence of enumerated steps is the defining characteristic of a procedure.

  • Standard: All laptops must be encrypted using AES-256

    Why this is correct

    A standard codifies a specific technical requirement, and this excerpt names the exact cryptographic algorithm (AES) and key strength (256-bit). Because it dictates a precise, measurable control—not a broad behavioral rule or optional advice—it belongs in the standard class. In security governance, standards are often derived from policies and are mandatory, so the word 'must' here enforces the technical baseline.

  • Guideline: It is recommended to use complex passwords

    Why this is correct

    A guideline is a recommended best practice that supports but does not mandate specific behaviors. The term 'recommended' clearly distinguishes this from a policy, which would use 'must' or 'shall,' and from a standard, which would specify measurable technical details. Organizations use guidelines like complex password usage to improve security posture while allowing flexibility in implementation.

  • Procedure: All employees must use multi-factor authentication

    Why it's wrong here

    Classifying this excerpt as a Procedure is incorrect because the statement merely declares a mandatory requirement; it does not outline the operational steps needed to enable multi-factor authentication. A procedure would say things like 'open the security portal, select MFA, then choose an authenticator app'—not just 'must use.' Since 'must' expresses an enforced rule, the correct classification is Policy, not Procedure.

  • Policy: It is recommended to use complex passwords

    Why it's wrong here

    Calling this a Policy is incorrect because 'recommended' explicitly marks the statement as advisory rather than mandatory. Policies are authoritative rules that require compliance, whereas guidelines offer voluntary best practices to improve security. As a suggestion rather than an enforceable standard, this excerpt should be classified as a Guideline.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: May 17, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.