nerdexam
EC-Council

712-50 · Question #307

Which of the following is MOST likely to be discretionary?

The correct answer is C. Guidelines. Guidelines are discretionary by definition - they are recommended practices or suggestions that individuals may follow at their own judgment, rather than mandatory requirements. In security frameworks (like those from NIST or ISO), guidelines explicitly carry no enforcement…

Governance (Policy, Legal & Compliance)

Question

Which of the following is MOST likely to be discretionary?

Options

  • APolicies
  • BProcedures
  • CGuidelines
  • DStandards

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    76% (25)
  • D
    15% (5)

Explanation

Guidelines are discretionary by definition - they are recommended practices or suggestions that individuals may follow at their own judgment, rather than mandatory requirements. In security frameworks (like those from NIST or ISO), guidelines explicitly carry no enforcement authority and exist to assist rather than compel.

Policies (A) are wrong because they are mandatory, high-level directives issued by management that must be followed - non-compliance carries consequences. Procedures (B) are wrong because they are mandatory, step-by-step instructions for carrying out a specific task with no room for personal discretion. Standards (D) are wrong because they define mandatory, specific requirements (e.g., minimum password length) that everyone must meet uniformly.

Memory tip: Think of the acronym SPGP in order of decreasing rigidity - Standards and Policies are rigid, Guidelines are flexible, Procedures are rigid steps. Or simply remember: "Guidelines are just suggestions - you can use your own Gudgment."

Topics

#governance structures#policy vs guidelines#discretionary controls#security governance

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice