Which Document Specifies Estimated Hours for a Vendor Engagement?
A company is working with a vendor to perform a penetration test. Which of the following includes an estimate about the number of hours required to complete the engagement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to differentiate between high-level legal frameworks and granular project planning documents, where the primary trap is confusing operational scoping with confidentiality or performance guarantees.
This question assesses knowledge of vendor management documentation by asking which agreement outlines project scope and labor estimates. The community unanimously identifies the Statement of Work (SOW) as the correct choice due to its role in detailing hours, methodologies, and deliverables.
Test-takers occasionally choose SLA or NDA, incorrectly assuming that service level targets or non-disclosure terms naturally encompass time estimates, when these documents actually govern performance thresholds and information sharing restrictions rather than task breakdowns.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer: Statement of Work (SOW)
The Statement of Work (SOW) is a formal document that defines the specific tasks, deliverables, timelines, and resource requirements for a project or vendor engagement. In the context of a penetration test, the SOW explicitly outlines the estimated number of hours, testing methodologies, target systems, rules of engagement, and final deliverables. As noted by the community, the SOW serves as the operational blueprint that translates business needs into actionable technical steps, making it the definitive source for labor and time projections [[2], [3]].Why Other Options Are Incorrect
- Business Partnership Agreement (BPA): This is a high-level contract establishing a strategic relationship between two organizations. It covers general terms, revenue sharing, or long-term collaboration goals, but lacks the granular project details like hourly estimates.
- Service Level Agreement (SLA): An SLA defines measurable performance metrics and uptime guarantees for ongoing services. While it may reference response times or availability windows, it does not specify the total hours required to complete a discrete project like a penetration test.
- Non-Disclosure Agreement (NDA): An NDA is a legal instrument designed to protect confidential information shared during negotiations or engagements. It strictly governs data privacy and secrecy obligations, containing zero information regarding project scope, scheduling, or labor estimates.
Official Reference
- NIST Special Publication 800-115: Technical Guide to Information Security Testing and Assessment
- CompTIA Security+ SY0-701 Objective 4.1: Compare and contrast types of security assessments
- ISO/IEC 27001:2022 Clause 6.1.2 - Information security risk assessment processes
Exam Strategy
When encountering contract-related questions on SY0-701, immediately categorize each option by its primary function: legal protection, performance measurement, or operational planning. Always match the keyword in the stem to the document type that handles granular execution details rather than broad organizational policies.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →