SY0-701 exam dumps

SY0-701 practice question 403 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 403

Single answerGuidelines

A security manager is updating the organization's policy framework after an internal audit found that several technical teams were treating broad security expectations as if they were mandatory step-by-step requirements. The manager wants to publish a document that recommends preferred ways to secure systems, allows flexibility when different technologies are used, and supports consistent decision-making without creating hard enforcement requirements. Which type of document should the manager publish?

  1. A

    Guidelines

  2. B

    Standards

  3. C

    Procedures

  4. D

    Baselines

Show answer and explanation

Correct answer: A

Explanation

The best answer is Guidelines because the scenario emphasizes recommended practices, flexibility, and nonmandatory direction. In common security governance models, policies set high-level management intent, standards define mandatory requirements, baselines establish minimum configurations, procedures provide step-by-step instructions, and guidelines offer advisory recommendations. This distinction is consistent with common security governance best practices referenced in industry frameworks and training materials used in Security+ preparation. The key clue is that the manager wants consistency and informed decision-making without creating binding technical requirements, which is the purpose of guidelines.

  • A. Correct.

    Correct. Guidelines are recommended practices that provide direction and advice but are not mandatory requirements. They are useful when an organization wants to encourage consistency and good security decisions while still allowing teams to adapt to different technical environments. In Security+ terminology, guidelines help shape implementation without imposing strict compliance obligations.

  • B. Incorrect.

    Incorrect. Standards are mandatory rules that specify required controls, configurations, or behaviors. If the organization published standards, teams would be expected to comply with them unless a formal exception process existed. That would not meet the stated goal of flexibility without hard enforcement.

  • C. Incorrect.

    Incorrect. Procedures are detailed, step-by-step instructions for performing a specific task, such as how to provision an account or rotate encryption keys. The scenario specifically says the manager does not want a mandatory step-by-step document, so procedures are not the best answer.

  • D. Incorrect.

    Incorrect. Baselines define a minimum level of security configuration or performance, such as a secure workstation build or minimum password settings. Although baselines can support consistency, they are typically treated as required starting points rather than optional recommendations, so they do not match the scenario as well as guidelines.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam