nerdexam
CompTIA

CAS-003 · Question #718

The Chief Information Security Officer (CISO) is preparing a requirements matrix scorecard for a new security tool the company plans to purchase. Feedback from which of the following documents will…

The correct answer is D. RFP. During vendor selection, an RFP solicits detailed proposals from vendors that can be evaluated and scored against a requirements matrix scorecard.

Risk Management

Question

The Chief Information Security Officer (CISO) is preparing a requirements matrix scorecard for a new security tool the company plans to purchase. Feedback from which of the following documents will provide input for the requirements matrix scorecard during the vendor selection process?

Options

  • AMSA
  • BRFQ
  • CRFI
  • DRFP

How the community answered

(34 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    94% (32)

Why each option

During vendor selection, an RFP solicits detailed proposals from vendors that can be evaluated and scored against a requirements matrix scorecard.

AMSA

A Master Service Agreement (MSA) is a contract framework established after a vendor has already been selected, not a solicitation document used to gather vendor input during evaluation.

BRFQ

A Request for Quotation (RFQ) solicits pricing information only and does not provide the detailed technical capability descriptions needed to score a requirements matrix.

CRFI

A Request for Information (RFI) is used early in market research to gather general information about vendor capabilities, but it is an informal inquiry rather than a formal solicitation that produces scorable proposals.

DRFPCorrect

A Request for Proposal (RFP) asks vendors to submit detailed technical and business proposals in response to specified requirements. The vendor responses to an RFP provide the direct input needed to populate and score a requirements matrix scorecard, enabling structured, side-by-side comparison of competing vendors.

Concept tested: Vendor selection documentation and procurement process

Source: https://www.nist.gov/system/files/documents/2017/05/09/ven-mgmt-procure-gd-final.pdf

Topics

#vendor selection#RFP#procurement#security requirements

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice