SY0-701 exam dumps

SY0-701 practice question 446 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 446

Single answer

A company is hiring a third-party security firm to perform a six-week penetration test and vulnerability assessment of its internet-facing applications. The legal team has already signed a master agreement with the vendor that covers general legal terms, payment conditions, liability, and dispute handling for future engagements. The security manager now needs a document that defines the specific scope of this project, including the target IP ranges, testing window, deliverables, reporting requirements, and rules of engagement. Which agreement type should the security manager use?

  1. A

    Service-level agreement (SLA)

  2. B

    Statement of work (SOW)

  3. C

    Memorandum of understanding (MOU)

  4. D

    Non-disclosure agreement (NDA)

Show answer and explanation

Correct answer: B

Explanation

The best answer is the Statement of Work (SOW). In practice, organizations often use an MSA to establish the overarching legal and commercial framework for a vendor relationship, then issue a SOW or work order for each specific engagement. For security assessments, the SOW should clearly document in-scope systems, out-of-scope systems, testing dates and hours, escalation contacts, deliverables, authorization boundaries, and rules of engagement to reduce legal and operational risk. An NDA may also be used alongside the SOW to protect sensitive information, and an SLA is more appropriate for recurring service performance metrics rather than project scoping. This aligns with common vendor management and contracting practices used in security operations and assessments.

  • A. Incorrect.

    Incorrect. An SLA defines measurable service performance expectations, such as uptime, response time, and support commitments. While an SLA may be relevant for managed security services, it does not typically define the detailed project scope, test boundaries, deliverables, and rules of engagement for a one-time penetration test engagement.

  • B. Correct.

    Correct. A statement of work (SOW), sometimes paired with or referenced by a work order, defines the specific work to be performed under an existing broader agreement such as an MSA. In this scenario, the company already has a master agreement in place, and it now needs project-specific details like scope, schedule, targets, deliverables, and engagement rules. That is exactly what an SOW is used for.

  • C. Incorrect.

    Incorrect. An MOU generally documents mutual intentions, roles, or understandings between parties, often when the relationship is cooperative rather than strictly contractual. It is usually higher level and less suitable for defining detailed penetration testing scope and legally enforceable project deliverables.

  • D. Incorrect.

    Incorrect. An NDA protects confidential information shared between parties. It would be appropriate in a penetration testing engagement because sensitive findings, architecture details, and credentials may be exposed, but it does not define the actual project tasks, test scope, schedule, and deliverables.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam