Courseiva

SY0-701 Security Program Management and Oversight Practice Question

Match each requirement or instruction to the correct governance document type. Use each document type once.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Policy

Standard

Procedure

Guideline

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Policy: High-level statement of management intent

These matches align with common governance document types in IT security frameworks: policy provides high-level direction, standard sets mandatory rules, procedure gives step-by-step instructions, guideline offers non-mandatory recommendations, baseline defines minimum configurations, and framework provides a structured approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy: High-level statement of management intent

    Why this is correct

    Policy is correctly defined as a high-level statement of management intent. It expresses the organization's security goals and expectations without specifying technical implementations, allowing flexibility in how objectives are met. Policies are approved by senior management and serve as the authoritative basis for developing standards, procedures, and guidelines.

  • Standard: Mandatory rules that must be followed

    Why this is correct

    Standard is correctly defined as mandatory rules that must be followed. Standards convert policy intent into concrete, enforceable requirements, such as a minimum 12-character password length or AES-256 encryption, which all systems must satisfy. Noncompliance with a standard is a formal violation and can trigger corrective action, unlike guidelines that merely suggest optional approaches.

  • Procedure: Recommended best practices, not mandatory

    Why it's wrong here

    Procedure: Recommended best practices, not mandatory — this is incorrect because it describes a guideline, not a procedure. Procedures are obligatory, step-by-step instructions that detail the precise sequence of actions needed to complete a task, such as applying a security patch or handling a help desk ticket. They are not discretionary, and skipping a step can result in failed control implementation or compliance issues.

  • Guideline: Step-by-step instructions for performing a task

    Why it's wrong here

    Guideline: Step-by-step instructions for performing a task — this is incorrect because it describes a procedure, not a guideline. Guidelines are recommended, non-binding advice that offer general direction or alternative approaches, such as secure configuration suggestions, without prescribing exact technical commands. Because they lack mandatory language and sequential steps, they should not be confused with procedures, which are prescriptive and operational.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.