nerdexam
CompTIA

SY0-501 · Question #507

A procedure differs from a policy in that it:

The correct answer is C. provides step-by-step instructions for performing a task. In security governance, different documents serve distinct purposes. A procedure is specifically an operational document that provides detailed, step-by-step instructions for carrying out a specific task.

Submitted by tunde_lagos· Mar 4, 2026Security program management and oversight

Question

A procedure differs from a policy in that it:

Options

  • Ais a high-level statement regarding the company's position on a topic.
  • Bsets a minimum expected baseline of behavior.
  • Cprovides step-by-step instructions for performing a task.
  • Ddescribes adverse actions when violations occur.

How the community answered

(50 responses)
  • A
    10% (5)
  • B
    2% (1)
  • C
    82% (41)
  • D
    6% (3)

Why each option

In security governance, different documents serve distinct purposes. A procedure is specifically an operational document that provides detailed, step-by-step instructions for carrying out a specific task.

Ais a high-level statement regarding the company's position on a topic.

A high-level statement regarding the company's position on a topic describes a policy, not a procedure - policies set the organizational intent and direction without specifying how tasks are carried out.

Bsets a minimum expected baseline of behavior.

Setting a minimum expected baseline of behavior describes a standard, which defines the specific mandatory requirements that support a policy rather than providing step-by-step operational guidance.

Cprovides step-by-step instructions for performing a task.Correct

A procedure is defined as a detailed, step-by-step document that instructs personnel exactly how to perform a specific task or process, such as how to respond to a security incident or how to onboard a new user. Unlike policies, procedures are tactical and operational in nature, translating high-level policy requirements into actionable instructions. This distinction is fundamental to security governance frameworks and separates procedures from policies, standards, and guidelines.

Ddescribes adverse actions when violations occur.

Describing adverse actions when violations occur relates to enforcement mechanisms or disciplinary procedures within a policy framework, not the operational definition of a procedure.

Concept tested: Distinguishing policy, standard, procedure, and guideline

Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final

Topics

#policy#procedure#governance#documentation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice