SY0-701 Security Program Management and Oversight Practice Question
The service desk needs a document that tells analysts exactly how to verify a caller and reset a password for a locked account. Which document type should they use?
⚠ Common exam trap
Many exam-takers confuse a procedure with a policy or standard, as candidates often think a high-level policy is sufficient for operational tasks, but the exam requires recognizing that procedures are the only document type that mandates exact, ordered steps for a specific task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure, because it provides exact steps staff must follow in order
A procedure is the correct document type because it provides a step-by-step sequence of actions that staff must follow to complete a specific operational task, such as verifying a caller's identity and resetting a password. Unlike policies or standards, procedures are mandatory and detail the exact commands, verification checks, and escalation paths required to ensure consistent and secure execution of the task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it states the organization's high-level security expectations
Why it's wrong here
A policy expresses the organization's strategic security objectives and mandatory high-level rules (e.g., 'all remote access must be authenticated'), but it deliberately avoids operational detail. For the service desk, a policy would state that caller verification is required before resetting credentials, yet it would not list the verification tokens, the order of checks, or the actions to take when verification fails. That lack of concrete step-by-step guidance is why a policy alone cannot tell analysts exactly how to perform the workflow.
- ✗
Guideline, because it offers helpful suggestions that staff may choose to follow
Why it's wrong here
A guideline provides recommended practices and optional approaches that analysts are not strictly required to follow, such as suggesting a particular phrasing for caller verification. In a security-sensitive task like password reset, leaving the sequence optional introduces inconsistency and increases the risk that an analyst skips an identity check. Because the service desk needs a prescribed, enforceable procedure, a guideline's flexibility is insufficient.
- ✓
Procedure, because it provides exact steps staff must follow in order
Why this is correct
A procedure is the correct document type because it specifies a mandatory, repeatable sequence of detailed actions—such as 'verify two identity attributes, then reset the password, then log the incident ticket.' Procedures remove ambiguity, ensure every analyst performs the task in the same secure order, and support auditability and accountability. This makes a procedure far more actionable than a policy, standard, or guideline for service desk workflows.
- ✗
Standard, because it defines a general topic without operational detail
Why it's wrong here
A standard defines mandatory technical specifications, baselines, or security requirements—such as 'minimum password length is 12 characters' or 'TLS 1.2 or higher must be used'—but it does not describe the order of operational actions. While a standard would list prerequisites for the password environment, it would not walk an analyst through the call-verification and reset steps. Thus, a standard lacks the sequential workflow detail required by the service desk.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Procedure
A documented set of step-by-step instructions for performing a specific task or handling a particular situation in an IT environment.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.