712-50 exam dumps

712-50 practice question 427 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 427

Single answerUnderstand the basic procurement concepts such as Statement of Objectives (SOO), Statement of Work (SOW), and Total Cost of Ownership (TCO)

A newly appointed CISO is sponsoring the replacement of a legacy Security Information and Event Management (SIEM) platform. The procurement team wants to accelerate vendor competition and avoid locking the organization into one supplier's technical approach. The CISO also wants the final business case to reflect not only subscription fees, but integration, staffing, training, migration, and ongoing support costs over the platform's expected life. Which approach is MOST appropriate?

  1. A

    Issue a Statement of Objectives (SOO) describing desired security outcomes and mission needs, ask vendors to propose their own solution approach, and evaluate options using Total Cost of Ownership (TCO) across the expected lifecycle.

  2. B

    Issue a detailed Statement of Work (SOW) that prescribes the exact SIEM architecture, tool configuration, and implementation steps, and compare vendors primarily on lowest initial purchase price.

  3. C

    Issue a sole-source request based on the incumbent SIEM design to reduce transition risk, and use annual operating expense as the main cost metric because capital expenses are sunk costs.

  4. D

    Issue a request for proposal without either a SOO or SOW so vendors are unconstrained, and evaluate proposals using return on investment (ROI) only because it already includes all lifecycle cost elements.

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because it correctly applies both procurement framing and cost evaluation concepts. A SOO is designed to express high-level desired outcomes, allowing vendors to propose innovative or tailored solutions. This is especially useful when leadership wants to preserve competition and avoid over-constraining the market with a predefined design. By contrast, a SOW is more appropriate when the buyer already knows the exact work to be performed, specific tasks, and required deliverables.

TCO is the appropriate cost lens for this scenario because a security platform decision should account for the full lifecycle, not just acquisition price. For a SIEM, relevant TCO elements typically include licensing or subscription, implementation services, migration from the legacy platform, data integration, infrastructure or cloud consumption, personnel to operate and tune the system, training, maintenance, support, and eventual upgrade or transition costs. This aligns with standard procurement and financial management practice, which emphasizes lifecycle costing for capital and technology decisions.

From a best-practice perspective, procurement guidance in both public- and private-sector sourcing distinguishes outcome-based requirement statements from prescriptive work statements, and financial governance commonly recommends lifecycle cost analysis for technology selection. In short: use a SOO when you want vendors to propose how to meet the objective; use a SOW when you already know exactly what must be done; and use TCO to compare the true economic impact of competing solutions.

  • A. Correct.

    Correct. A Statement of Objectives (SOO) is outcome-focused and is commonly used when the buyer wants industry to propose the best method for meeting mission or business needs rather than dictating the technical solution. That fits the scenario because the CISO wants to encourage competition and avoid prematurely constraining vendors. Using Total Cost of Ownership (TCO) is also appropriate because TCO considers the full lifecycle cost of the SIEM initiative, including acquisition, implementation, migration, integration, training, staffing, operations, maintenance, and support, not just subscription or purchase price.

  • B. Incorrect.

    Incorrect. A Statement of Work (SOW) is useful when the organization knows exactly what tasks, deliverables, and methods it wants performed. In this scenario, however, the goal is to avoid locking into one technical approach and let vendors propose alternatives, so an overly prescriptive SOW would work against that objective. In addition, evaluating mainly on initial purchase price reflects a common procurement mistake; for security platforms such as SIEMs, implementation, tuning, integration, data ingestion, and ongoing operational effort often represent a large portion of total cost.

  • C. Incorrect.

    Incorrect. Sole-sourcing based on the incumbent design reduces competition and may reinforce vendor lock-in, which directly conflicts with the scenario. Also, relying mainly on annual operating expense is too narrow. TCO is intended to capture all relevant lifecycle costs, including migration and transition costs, capital and operating expenditures, support, and personnel impacts. Treating capital expenses as irrelevant because they are 'sunk' misunderstands the business-case decision, which should assess future costs of the new procurement option over its useful life.

  • D. Incorrect.

    Incorrect. A procurement package generally needs a clear description of requirements, whether framed as objectives or detailed work. Omitting both a SOO and a SOW would create ambiguity, inconsistent proposals, and poor evaluation quality. ROI is a financial metric that compares benefits to costs; it is not a substitute for TCO. ROI may be useful in a business case, but it does not, by itself, enumerate or ensure inclusion of all lifecycle cost elements.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam