Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

The SOC is writing step-by-step instructions for responding to a suspected malware infection on a laptop. The document should tell analysts exactly what to do first, second, and third during triage and containment. Which governance artifact should they create?

⚠ Common exam trap

The SY0-701 exam often tests the distinction between high-level governance documents (policies, standards) and operational documents (procedures, guidelines), and the trap here is that candidates confuse a procedure with a guideline because both provide instructions, but a procedure is mandatory and ordered, while a guideline is advisory and flexible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Procedure, because it gives a repeatable sequence of actions for a specific task.

A procedure is the correct governance artifact because it provides a detailed, step-by-step sequence of actions for a specific task—in this case, triaging and containing a suspected malware infection on a laptop. Unlike policies or standards, which set high-level intent or goals, a procedure ensures repeatable and consistent execution by analysts during incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy, because it states the organization's broad security intent.

    Why it's wrong here

    A policy is a high-level governance document that communicates the organization's security intent, scope, and authority, such as 'all incidents must be reported and handled'. It does not provide the operational details, tool-specific commands, or chronological action list needed for execution. While it mandates that incident response exist, it leaves the 'how' to lower-level documents, making it unsuitable as a step-by-step instruction set.

  • Procedure, because it gives a repeatable sequence of actions for a specific task.

    Why this is correct

    A procedure is the right artifact when the team needs exact, repeatable instructions. In incident response, analysts need a consistent sequence for triage, containment, escalation, and evidence handling so that actions are predictable and auditable. Procedures support operational consistency and reduce confusion during stressful events, which is why they fit this scenario better than policies or guidelines.

  • Guideline, because it offers optional advice that analysts may choose to follow.

    Why it's wrong here

    Guidelines are discretionary recommendations designed to be adapted to the situation, not mandated steps. In incident response, treating a guideline as the operating procedure would allow analysts to skip evidence preservation steps or containment actions in stressful moments, leading to inconsistent and unverifiable outcomes. Unlike a procedure, a guideline does not impose a strict order or mandatory requirements, so it cannot ensure repeatable, auditable response actions.

  • Standard, because it defines the organization's security goals at a high level.

    Why it's wrong here

    A standard defines mandatory technical or process requirements such as encryption algorithms, logging thresholds, or access-control baselines that must be met. It serves as a compliance yardstick for systems and controls, but it is not a workflow and does not enumerate the sequence of actions an analyst should take during an incident. Standards like NIST SP 800-53 complement a procedure by specifying configuration requirements, but they are too static and requirements-focused to guide dynamic incident handling.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.