SY0-701 Question 404
Single answerGuidelinesA healthcare organization is updating its security documentation after an internal audit found that different teams were handling mobile device configuration inconsistently. The security manager wants to publish a document that recommends baseline practices such as enabling screen locks, requiring device encryption, disabling sideloading of applications, and using the company MDM platform. However, some business units may need approved exceptions based on operational requirements. Which type of document should the security manager publish to address this need?
- A
Policy
- B
Standard
- C
Guideline
- D
Procedure
Show answer and explanation
Correct answer: C
Explanation
The best answer is Guideline. In Security+ governance documentation, policies are high-level statements of management intent, standards are mandatory and specific requirements, guidelines are recommended but not strictly required practices, and procedures are detailed step-by-step instructions. Because the scenario emphasizes recommended baseline practices with room for approved exceptions, a guideline is the best fit. This aligns with common security governance models used in industry and with broadly accepted documentation hierarchies reflected in security frameworks and organizational governance practices, where guidelines support consistent implementation without imposing rigid mandatory controls in every case.
- A. Incorrect.
Policy is incorrect because a policy is a high-level management statement that defines organizational intent, rules, and direction. It would state that mobile devices must be secured, but it is typically less suited for publishing recommended practices that allow flexibility and exceptions at the implementation level.
- B. Incorrect.
Standard is incorrect because a standard is normally mandatory and specific. If the organization needed a fixed, uniform requirement with little variation, a standard would be appropriate. In this scenario, the security manager wants recommended baseline practices that teams should follow when possible, while still allowing approved exceptions.
- C. Correct.
Guideline is correct because guidelines provide recommended actions and best practices rather than strictly mandatory requirements. They are useful when consistency is desired but some flexibility is necessary for differing business or operational needs. That matches the scenario of publishing security recommendations for mobile devices while permitting approved exceptions.
- D. Incorrect.
Procedure is incorrect because a procedure gives step-by-step instructions for completing a task, such as exactly how to enroll a phone in MDM or verify encryption status. The scenario is asking for a document that recommends security practices across teams, not a task-specific implementation checklist.