Courseiva
Security and Risk ManagementeasyMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Which document provides detailed step-by-step instructions for performing a specific security task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Procedure

A procedure is a detailed, step-by-step document that describes how to perform a task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why it's wrong here

    A policy is a high-level, mandatory statement issued by management that outlines the organization's strategic goals and acceptable behavior regarding information security. It defines *what* must be achieved and *why* it is important, establishing the overarching rules and principles. Policies do not provide granular, step-by-step instructions for specific tasks, making them unsuitable for detailed operational guidance. Instead, they serve as the foundational directive upon which more detailed documents are built.

  • Procedure

    Why this is correct

    A procedure is a mandatory, detailed set of step-by-step instructions that describes *how* to perform a specific task or process consistently and securely. It outlines the exact actions to be taken, the order in which they should occur, and often specifies roles, responsibilities, and tools required. Procedures ensure uniformity, repeatability, and compliance with established policies and standards, directly addressing the need for explicit operational guidance for security functions.

  • Standard

    Why it's wrong here

    A standard is a mandatory document that specifies uniform requirements for hardware, software, configurations, or processes within an organization. It dictates *what* specific technologies or settings must be used to comply with policies, ensuring consistency and interoperability across systems. While standards establish strict criteria that must be met, they do not typically provide the sequential, step-by-step instructions on *how* to implement or achieve those requirements, focusing instead on the required attributes.

  • Guideline

    Why it's wrong here

    A guideline offers recommended actions and best practices that are flexible and non-mandatory, providing advice on how to achieve a policy objective. It suggests various ways to approach a task or situation, allowing for discretion and adaptation based on specific circumstances and professional judgment. Unlike procedures, guidelines do not dictate a rigid sequence of steps but rather offer helpful suggestions and general principles for consideration, promoting flexibility rather than strict adherence.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.