Courseiva
General Security ConceptseasyMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

The help desk needs a document that describes the exact steps for verifying a caller and resetting a password. What type of document should they use?

⚠ Common exam trap

Many candidates confuse a procedure (the 'how') with a policy (the 'what'), as candidates often think a policy document contains step-by-step instructions, but policies only set the rules, not the exact steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Procedure

A procedure provides the exact, step-by-step instructions needed for a specific task, such as verifying a caller's identity and resetting a password. This is distinct from a policy, which states high-level rules, or a standard, which defines mandatory technical requirements. The help desk needs a documented sequence of actions, which is the definition of a procedure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why it's wrong here

    Policy is a high-level directive that expresses management's intent and mandatory requirements, such as 'all password resets must verify identity.' It establishes the rules and boundaries but deliberately omits the granular sequence of actions that a technician must follow, so it cannot serve as the exact step-by-step document the help desk needs. A policy tells staff what to do and why, not precisely how to do it in every situation.

  • Procedure

    Why this is correct

    A procedure is the correct document because it gives step-by-step instructions for completing a task in a consistent way. In this case, the help desk needs a repeatable method for identity verification, password reset, and ticket documentation. Procedures help reduce errors and ensure staff follow the same approved process each time.

  • Standard

    Why it's wrong here

    A standard defines specific technical criteria, configurations, or formats that must be met, such as minimum password length, encryption algorithms, or naming conventions. It focuses on the measurable attributes of the result or the environment, not on the workflow of performing a task like verifying an identity or documenting a ticket. While the help desk might be bound by certain standards, those standards do not describe the exact ordered steps required to complete the full procedure.

  • Guideline

    Why it's wrong here

    A guideline offers recommended, non-mandatory advice on how to handle a task, giving staff flexibility to adapt based on their judgment or context. Because it is intentionally loose and allows for alternative approaches, it cannot guarantee that every help desk technician will perform identity verification and password reset in the same exact way. The requirement is for a precise, repeatable process, which a guideline by design does not provide.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.