SY0-701 Security Program Management and Oversight Practice Question
The SOC is writing step-by-step instructions for responding to a suspected malware infection on a laptop. The document should tell analysts exactly what to do first, second, and third during triage and containment. Which governance artifact should they create?
⚠ Common exam trap
The SY0-701 exam often tests the distinction between high-level governance documents (policies, standards) and operational documents (procedures, guidelines), and the trap here is that candidates confuse a procedure with a guideline because both provide instructions, but a procedure is mandatory and ordered, while a guideline is advisory and flexible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedure, because it gives a repeatable sequence of actions for a specific task.
A procedure is the correct governance artifact because it provides a detailed, step-by-step sequence of actions for a specific task—in this case, triaging and containing a suspected malware infection on a laptop. Unlike policies or standards, which set high-level intent or goals, a procedure ensures repeatable and consistent execution by analysts during incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, because it states the organization's broad security intent.
Why it's wrong here
A policy is a high-level governance document that communicates the organization's security intent, scope, and authority, such as 'all incidents must be reported and handled'. It does not provide the operational details, tool-specific commands, or chronological action list needed for execution. While it mandates that incident response exist, it leaves the 'how' to lower-level documents, making it unsuitable as a step-by-step instruction set.
- ✓
Procedure, because it gives a repeatable sequence of actions for a specific task.
Why this is correct
A procedure is the right artifact when the team needs exact, repeatable instructions. In incident response, analysts need a consistent sequence for triage, containment, escalation, and evidence handling so that actions are predictable and auditable. Procedures support operational consistency and reduce confusion during stressful events, which is why they fit this scenario better than policies or guidelines.
- ✗
Guideline, because it offers optional advice that analysts may choose to follow.
Why it's wrong here
Guidelines are discretionary recommendations designed to be adapted to the situation, not mandated steps. In incident response, treating a guideline as the operating procedure would allow analysts to skip evidence preservation steps or containment actions in stressful moments, leading to inconsistent and unverifiable outcomes. Unlike a procedure, a guideline does not impose a strict order or mandatory requirements, so it cannot ensure repeatable, auditable response actions.
- ✗
Standard, because it defines the organization's security goals at a high level.
Why it's wrong here
A standard defines mandatory technical or process requirements such as encryption algorithms, logging thresholds, or access-control baselines that must be met. It serves as a compliance yardstick for systems and controls, but it is not a workflow and does not enumerate the sequence of actions an analyst should take during an incident. Standards like NIST SP 800-53 complement a procedure by specifying configuration requirements, but they are too static and requirements-focused to guide dynamic incident handling.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.