Drag a concept onto its matching description — or click a concept then click the description.
Standard
Procedure
Guideline
Exception
Policy
1. All company laptops must use full-disk encryption, automatic screen locking after 10 minutes, and the approved EDR agent. 2. To replace a lost MFA token, the help desk must verify identity, disable the old token, and re-enroll the user before access is restored. 3. Users should avoid storing confidential files on removable media unless there is a documented business need. 4. The engineering team may use one unsupported browser plug-in on two workstations for 30 days while a redesign is completed. 5. Remote access is allowed only through the approved VPN with MFA.
Match each excerpt from a small enterprise security program to the correct governance artifact.
Drag a concept onto its matching description — or click a concept then click the description.
Standard
Procedure
Guideline
Exception
Policy
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Policy: All employees must use multi-factor authentication
Policy defines mandatory rules; Procedure gives step-by-step instructions; Standard specifies technical requirements; Guideline offers best practices.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Policy: All employees must use multi-factor authentication
Why this is correct
A policy is a formal, mandatory statement of management intent, and 'must' makes this requirement non-negotiable for all employees. It establishes an organization-wide rule without prescribing the underlying mechanics, such as which MFA app or hardware token to use—that level of detail would live in a standard or procedure. Therefore, classifying this as Policy is correct because it sets an enforceable expectation.
Procedure: To reset a password, follow steps 1-5
Why this is correct
A procedure is a detailed, ordered sequence of actions for completing a specific task, and the phrase 'follow steps 1-5' signals exactly that. Unlike a policy (a rule) or a standard (a technical requirement), this excerpt instructs the user how to perform a password reset step by step. The presence of enumerated steps is the defining characteristic of a procedure.
Standard: All laptops must be encrypted using AES-256
Why this is correct
A standard codifies a specific technical requirement, and this excerpt names the exact cryptographic algorithm (AES) and key strength (256-bit). Because it dictates a precise, measurable control—not a broad behavioral rule or optional advice—it belongs in the standard class. In security governance, standards are often derived from policies and are mandatory, so the word 'must' here enforces the technical baseline.
Guideline: It is recommended to use complex passwords
Why this is correct
A guideline is a recommended best practice that supports but does not mandate specific behaviors. The term 'recommended' clearly distinguishes this from a policy, which would use 'must' or 'shall,' and from a standard, which would specify measurable technical details. Organizations use guidelines like complex password usage to improve security posture while allowing flexibility in implementation.
Procedure: All employees must use multi-factor authentication
Why it's wrong here
Classifying this excerpt as a Procedure is incorrect because the statement merely declares a mandatory requirement; it does not outline the operational steps needed to enable multi-factor authentication. A procedure would say things like 'open the security portal, select MFA, then choose an authenticator app'—not just 'must use.' Since 'must' expresses an enforced rule, the correct classification is Policy, not Procedure.
Policy: It is recommended to use complex passwords
Why it's wrong here
Calling this a Policy is incorrect because 'recommended' explicitly marks the statement as advisory rather than mandatory. Policies are authoritative rules that require compliance, whereas guidelines offer voluntary best practices to improve security. As a suggestion rather than an enforceable standard, this excerpt should be classified as a Guideline.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: May 17, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.