Procedure vs Policy: Which Document Provides Step-by-Step Instructions?
The help desk needs a document that tells analysts exactly how to verify a caller, reset a password, and record the ticket when a user is locked out. What type of document is this?
Quick Answer
The answer is a procedure. A procedure is the correct choice because it provides the precise, step-by-step instructions needed to complete a specific operational task, such as verifying a caller’s identity, resetting a password, and recording a ticket. This contrasts with a policy, which defines high-level rules and strategic intent—like “all password resets must be authenticated”—but does not detail the exact actions to take. On the Security+ SY0-701 exam, this distinction tests your understanding of security documentation hierarchy, often appearing in scenario-based questions where you must choose between policy, procedure, guideline, or standard. A common trap is confusing a procedure with a policy when the question emphasizes mandatory steps; remember that policies state the “what” and “why,” while procedures deliver the “how.” For a quick memory tip, think of the word “procedure” as containing “proceed”—it tells you exactly how to proceed through a task.
⚠ Common exam trap
Test-takers frequently confuse 'procedure' with 'policy' because both are security documents, but a policy sets the 'what' and 'why' (e.g., 'passwords must be reset securely'), while a procedure defines the 'how' (e.g., 'call the user back at their verified phone number before resetting').
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure
A procedure is the correct type of document because it provides step-by-step instructions for performing a specific task, such as verifying a caller's identity, resetting a password, and recording a ticket. Unlike a policy, which states high-level rules, a procedure details the exact actions to take in a given scenario, making it ideal for help desk operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Procedure
Why this is correct
A procedure is the right document when staff need exact step-by-step instructions. In this situation, the help desk needs a repeatable process for identity verification, password reset actions, and documentation requirements. Procedures reduce mistakes because they tell employees what to do in sequence rather than leaving the process open to interpretation.
- ✗
Policy
Why it's wrong here
A policy would describe the organization's intent, but not the detailed steps for the help desk.
- ✗
Standard
Why it's wrong here
A standard would set required minimums, but it would not provide the full workflow for handling calls.
- ✗
Guideline
Why it's wrong here
A guideline can help with recommendations, but it is too flexible for a required support workflow.
Go deeper
Related to this question
Learn chapter
Phishing Simulations and Awareness
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Procedure
A documented set of step-by-step instructions for performing a specific task or handling a particular situation in an IT environment.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. The service desk needs a document that tells analysts exactly how to verify a caller and reset a password for a locked account. Which document type should they use?
easy- A.Policy, because it states the organization's high-level security expectations
- B.Guideline, because it offers helpful suggestions that staff may choose to follow
- ✓ C.Procedure, because it provides exact steps staff must follow in order
- D.Standard, because it defines a general topic without operational detail
Why C: A procedure is the correct document type because it provides a step-by-step sequence of actions that staff must follow to complete a specific operational task, such as verifying a caller's identity and resetting a password. Unlike policies or standards, procedures are mandatory and detail the exact commands, verification checks, and escalation paths required to ensure consistent and secure execution of the task.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.