SY0-701 General Security Concepts Practice Question
The help desk needs a document that describes the exact steps for verifying a caller and resetting a password. What type of document should they use?
⚠ Common exam trap
Many candidates confuse a procedure (the 'how') with a policy (the 'what'), as candidates often think a policy document contains step-by-step instructions, but policies only set the rules, not the exact steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure
A procedure provides the exact, step-by-step instructions needed for a specific task, such as verifying a caller's identity and resetting a password. This is distinct from a policy, which states high-level rules, or a standard, which defines mandatory technical requirements. The help desk needs a documented sequence of actions, which is the definition of a procedure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy
Why it's wrong here
Policy is a high-level directive that expresses management's intent and mandatory requirements, such as 'all password resets must verify identity.' It establishes the rules and boundaries but deliberately omits the granular sequence of actions that a technician must follow, so it cannot serve as the exact step-by-step document the help desk needs. A policy tells staff what to do and why, not precisely how to do it in every situation.
- ✓
Procedure
Why this is correct
A procedure is the correct document because it gives step-by-step instructions for completing a task in a consistent way. In this case, the help desk needs a repeatable method for identity verification, password reset, and ticket documentation. Procedures help reduce errors and ensure staff follow the same approved process each time.
- ✗
Standard
Why it's wrong here
A standard defines specific technical criteria, configurations, or formats that must be met, such as minimum password length, encryption algorithms, or naming conventions. It focuses on the measurable attributes of the result or the environment, not on the workflow of performing a task like verifying an identity or documenting a ticket. While the help desk might be bound by certain standards, those standards do not describe the exact ordered steps required to complete the full procedure.
- ✗
Guideline
Why it's wrong here
A guideline offers recommended, non-mandatory advice on how to handle a task, giving staff flexibility to adapt based on their judgment or context. Because it is intentionally loose and allows for alternative approaches, it cannot guarantee that every help desk technician will perform identity verification and password reset in the same exact way. The requirement is for a precise, repeatable process, which a guideline by design does not provide.
Go deeper
Related to this question
Learn chapter
Cryptographic Key Management
Key term
Procedure
A documented set of step-by-step instructions for performing a specific task or handling a particular situation in an IT environment.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.