Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Which document should define mandatory settings such as full-disk encryption, a 10-minute screen-lock timeout, and removal of local administrator rights on company laptops?

⚠ Common exam trap

A common mix-up: candidates confuse 'policy' (high-level direction) with 'standard' (specific mandatory configuration), leading them to pick A when the question explicitly lists concrete, enforceable settings rather than general principles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Standard, because it defines specific required configurations that must be followed.

A standard defines mandatory, specific technical configurations that must be uniformly applied across all company laptops. The question lists concrete settings (full-disk encryption, 10-minute screen-lock timeout, removal of local admin rights) that are not open to interpretation, which aligns precisely with the role of a security standard in enforcing baseline compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy, because it explains the general direction but not the exact settings.

    Why it's wrong here

    A policy at the strategic level states the organization's security objectives and intended outcomes, such as 'all workstations must be secured,' but it deliberately avoids listing concrete technical parameters. Policies use non-technical language to communicate management expectations to a broad audience. Because a policy does not specify exact values like password length or encryption algorithm, it cannot serve as the document that mandates precise settings such as those referred to in the question.

  • Standard, because it defines specific required configurations that must be followed.

    Why this is correct

    This is correct because a standard turns policy into measurable, mandatory requirements. Exact settings such as encryption, screen-lock timing, and administrative restrictions belong in a standard since they must be applied consistently across similar systems. Standards help administrators implement security in a uniform, auditable way.

  • Procedure, because it lists the steps an end user should take every day.

    Why it's wrong here

    A procedure is a task-oriented checklist that describes the ordered actions an end user or administrator must take to complete a specific job, such as logging in, backing up data, or deploying a workstation. Procedures change frequently and are often system- or role-specific, and they do not establish the organization-wide, baseline security configuration that applies uniformly to every similar asset. Mandatory settings like 'full disk encryption' or 'screen-lock after 15 minutes' are compliance requirements, not step-by-step instructions, so a procedure is the wrong type of document.

  • Guideline, because it offers flexible recommendations rather than mandatory rules.

    Why it's wrong here

    A guideline provides recommendations and suggested best practices that may be adapted to an organization's unique needs, and entities can choose not to follow them without violating policy. By contrast, the question's 'must' language indicates a hard requirement, meaning non-compliance would be a policy violation and potentially an audit finding during an assessment. Because guidelines are explicitly non-mandatory and offer flexible alternatives, they cannot define settings that are required for every system, making them incorrect for this purpose.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.