712-50 exam dumps

712-50 practice question 426 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 426

Single answerUnderstand the basic procurement concepts such as Statement of Objectives (SOO), Statement of Work (SOW), and Total Cost of Ownership (TCO)

A newly appointed CISO is sponsoring a security operations modernization initiative and plans to outsource implementation of a managed detection and response capability. The procurement team asks the CISO to provide input before issuing a solicitation. Executive leadership wants vendors to propose innovative approaches, but Finance also requires a comparison that captures long-term cost impact rather than just acquisition price. Which action should the CISO take FIRST to best support these goals?

  1. A

    Develop a detailed Statement of Work (SOW) that prescribes the exact tools, staffing model, and implementation steps vendors must follow, then compare vendors primarily on purchase price

  2. B

    Develop a Statement of Objectives (SOO) describing the business and security outcomes required, allow vendors to propose their own technical approaches, and evaluate proposals using Total Cost of Ownership (TCO)

  3. C

    Ask each vendor to submit its own Statement of Work (SOW) without first defining organizational objectives, and select the vendor with the lowest first-year operating cost

  4. D

    Delay procurement documentation until a preferred vendor is identified, then create a Statement of Work (SOW) jointly to accelerate onboarding and avoid unnecessary evaluation effort

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use a Statement of Objectives (SOO) when the organization wants to describe desired mission or business outcomes and allow vendors flexibility in proposing methods, architectures, and service models. By contrast, a Statement of Work (SOW) is more prescriptive and typically defines tasks, deliverables, timelines, and performance requirements when the buyer knows what work should be performed and often how it should be executed. In this scenario, leadership explicitly wants innovation, so starting with a SOO is the better procurement approach.

The second key concept is Total Cost of Ownership (TCO). For security procurements, TCO goes beyond purchase price and should include implementation, integration with existing tooling, transition and onboarding, training, staffing impact, support, maintenance, service management overhead, contract renewal implications, scalability, and eventual exit or replacement costs. This is especially important in managed security services, where a low bid may become more expensive over time due to hidden operational dependencies or change fees.

This approach aligns with common procurement and acquisition best practices found in government and enterprise sourcing guidance: define outcomes clearly, preserve fair competition, evaluate based on lifecycle value, and avoid overemphasis on initial price when strategic services are involved.

  • A. Incorrect.

    Incorrect. A SOW is appropriate when the organization already knows exactly what work must be performed and wants to direct how it will be done. In this scenario, leadership wants vendors to propose innovative approaches, so an overly prescriptive SOW would constrain solution creativity. Comparing vendors primarily on purchase price also ignores TCO factors such as integration, transition, training, support, contract management, and future scaling costs.

  • B. Correct.

    Correct. A SOO is outcome-focused and is commonly used when the buyer wants industry to propose the best method for achieving defined objectives. That aligns with the executive request for innovation. Evaluating proposals using TCO is also appropriate because Finance wants a long-term cost view rather than a narrow acquisition-price comparison. TCO should include direct and indirect costs across the solution lifecycle, not just the initial contract amount.

  • C. Incorrect.

    Incorrect. Letting vendors draft a SOW without first establishing the organization's objectives creates a risk of misalignment with business and security needs. The core purpose of a SOO is to articulate desired outcomes so vendor responses can be evaluated against them. Choosing based only on first-year operating cost is a common mistake because low initial cost may mask higher lifecycle costs, lock-in, or expensive transition and support requirements.

  • D. Incorrect.

    Incorrect. Delaying formal procurement documentation until after identifying a preferred vendor weakens fairness, transparency, and due diligence in the sourcing process. It also increases the risk of selecting a vendor before requirements and evaluation criteria are properly defined. A CISO should help establish objectives and cost evaluation criteria before solicitation, not after a preferred supplier emerges.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam