Drag a concept onto its matching description — or click a concept then click the description.
Policy
Standard
Procedure
Guideline
Match each requirement or instruction to the correct governance document type. Use each document type once.
Drag a concept onto its matching description — or click a concept then click the description.
Policy
Standard
Procedure
Guideline
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Policy: High-level statement of management intent
These matches align with common governance document types in IT security frameworks: policy provides high-level direction, standard sets mandatory rules, procedure gives step-by-step instructions, guideline offers non-mandatory recommendations, baseline defines minimum configurations, and framework provides a structured approach.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Policy: High-level statement of management intent
Why this is correct
Policy is correctly defined as a high-level statement of management intent. It expresses the organization's security goals and expectations without specifying technical implementations, allowing flexibility in how objectives are met. Policies are approved by senior management and serve as the authoritative basis for developing standards, procedures, and guidelines.
Standard: Mandatory rules that must be followed
Why this is correct
Standard is correctly defined as mandatory rules that must be followed. Standards convert policy intent into concrete, enforceable requirements, such as a minimum 12-character password length or AES-256 encryption, which all systems must satisfy. Noncompliance with a standard is a formal violation and can trigger corrective action, unlike guidelines that merely suggest optional approaches.
Procedure: Recommended best practices, not mandatory
Why it's wrong here
Procedure: Recommended best practices, not mandatory — this is incorrect because it describes a guideline, not a procedure. Procedures are obligatory, step-by-step instructions that detail the precise sequence of actions needed to complete a task, such as applying a security patch or handling a help desk ticket. They are not discretionary, and skipping a step can result in failed control implementation or compliance issues.
Guideline: Step-by-step instructions for performing a task
Why it's wrong here
Guideline: Step-by-step instructions for performing a task — this is incorrect because it describes a procedure, not a guideline. Guidelines are recommended, non-binding advice that offer general direction or alternative approaches, such as secure configuration suggestions, without prescribing exact technical commands. Because they lack mandatory language and sequential steps, they should not be confused with procedures, which are prescriptive and operational.
Go deeper
Learn chapter
Compliance and Regulatory Frameworks
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Guideline
A guideline is a recommended set of best practices or instructions that provide direction for implementing, managing, or governing IT processes, without being strictly mandatory or enforced like a policy.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.