SY0-701 General Security Concepts Practice Question
Which document tells all employees what they are allowed and not allowed to do when using company systems?
⚠ Common exam trap
Test-takers frequently confuse 'policy' with 'procedure' or 'guideline,' thinking that step-by-step instructions or recommendations define allowed versus prohibited actions, but only a policy sets mandatory, enforceable rules for employee conduct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy
A policy is a high-level document that defines mandatory rules and expectations for employee behavior when using company systems. It specifies what is allowed and prohibited, such as acceptable use of email, internet browsing, and data handling, and is enforceable with consequences for non-compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policy
Why this is correct
A policy states the organization’s high-level rules and expectations for behavior. It tells employees what is permitted, prohibited, or required when using company systems, such as acceptable use, data handling, or password rules. Policies are approved by management and guide the rest of the security program.
- ✗
Procedure
Why it's wrong here
A procedure is a low-level, ordered sequence of actions used to complete a specific operational task, such as resetting a user's password or patching a server. It does not set organization-wide behavioral expectations or define what employees are broadly allowed or forbidden to do; it assumes the policy already exists and simply executes it. Procedures are also typically role-specific, so not every employee would follow the same procedure, making it the wrong document type for a universal employee rule set.
- ✗
Standard
Why it's wrong here
A standard is a technical specification or mandatory baseline, such as requiring AES-256 encryption or minimum password length, that supports a policy by defining exact, measurable requirements. It is usually targeted at system configurations, architectures, or specific controls rather than general workplace conduct or acceptable use. Because standards focus on 'how' a control must be implemented at the technical level, they are not the primary document that communicates to all employees what behaviors are permitted or prohibited.
- ✗
Guideline
Why it's wrong here
A guideline is a set of recommended, non-binding suggestions for how to approach a situation, often providing best practices without formal enforcement. Unlike a policy, a guideline explicitly lacks mandatory language and does not impose consequences for non-compliance, so it does not dictate what employees are allowed or not allowed to do. It is designed to offer flexibility and judgment, which makes it the opposite of the clear, enforceable rules that a policy establishes for the entire workforce.
Go deeper
Related to this question
Learn chapter
Open vs Closed Security Systems
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.