Courseiva
Security Program Management and OversightmediumMatchingObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Match each governance need to the document type that best fits. 1. All employees must follow rules for acceptable use of company systems. 2. Every company laptop must use full-disk encryption and a 14-character screen-lock PIN. 3. The service desk follows these exact steps to verify a caller before resetting MFA. 4. Admins are encouraged to place non-production test data in approved folders when practical.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Policy

Standard

Procedure

Guideline

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AUP: All employees must follow rules for acceptable use of company systems.

AUP is a policy for acceptable use; standards are mandatory requirements; procedures are step-by-step instructions; guidelines are recommendations; policy is a high-level directive; baseline defines minimum configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AUP: All employees must follow rules for acceptable use of company systems.

    Why this is correct

    An Acceptable Use Policy (AUP) is the authoritative document that defines permitted and prohibited behaviors when employees interact with company-owned IT resources, including internet browsing, email, and software installation. Because the governance need explicitly references 'rules for acceptable use of company systems,' the AUP is the most precise and commonly recognized document type for that exact purpose. This specificity distinguishes it from a generic policy, which spans multiple security domains and lacks the focused scope of an AUP.

  • Standards: Every company laptop must use full-disk encryption and a 14-character screen-lock PIN.

    Why this is correct

    A standard is a mandatory, often technical requirement that specifies exact configurations or controls that must be implemented to support an organization's security policy. The statement 'must use full-disk encryption and a 14-character screen-lock PIN' provides measurable, enforceable requirements for every laptop, which is the defining characteristic of a standard. Unlike a guideline, this is not optional, and unlike a baseline, it is not a mere minimum threshold—it is a fixed, absolute configuration.

  • Procedures: The service desk follows these exact steps to verify a caller before resetting MFA.

    Why this is correct

    A procedure is a detailed, chronological sequence of actions designed to accomplish a specific operational task, typically including decision points and expected outcomes. The service desk's 'exact steps to verify a caller before resetting MFA' is a textbook procedure because it prescribes the order and method for identity verification. This granular, step-by-step logic separates procedures from policies, standards, or guidelines, none of which provide operational instructions.

  • Guidelines: Admins are encouraged to place non-production test data in approved folders when practical.

    Why this is correct

    Guidelines are non-mandatory recommendations that suggest best practices, preferred approaches, or optional actions without imposing compliance obligations. The phrase 'encouraged to place non-production test data in approved folders when practical' clearly signals a recommendation, as 'encouraged' and 'when practical' allow for discretion based on context. A policy or standard would instead use 'must' or 'shall,' while a procedure would dictate the exact folder path and sequential placement steps.

  • Policy: All employees must follow rules for acceptable use of company systems.

    Why it's wrong here

    A policy is a high-level statement of management intent, goals, and overall direction, and an Acceptable Use Policy is indeed one subtype of that category. However, the governance need specifically calls for 'rules for acceptable use of company systems,' and the most exact, industry-recognized document type for that requirement is the AUP, not the broader policy label. Selecting 'policy' would be technically accurate yet imprecise, failing to capture the specialized purpose that makes the AUP the best-fit answer.

  • Baseline: Every company laptop must use full-disk encryption and a 14-character screen-lock PIN.

    Why it's wrong here

    A baseline defines the minimum set of security controls or configurations that must be in place, serving as a floor that may be strengthened, but it does not prescribe exact, fixed values. The statement 'every company laptop must use full-disk encryption and a 14-character screen-lock PIN' is a mandatory, specific configuration, not merely a minimum starting point. While a baseline might include such a requirement, the more precise document type for a fixed, enforceable technical requirement is a standard, making baseline the less accurate choice.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.