正解:A
A Statement of Work (SOW) is a formal document detailing the scope, deliverables, timeline, and estimated hours for services such as penetration testing engagements.
BPA (Blanket Purchase Agreement) covers recurring purchases, SLA (Service Level Agreement) defines service quality expectations, and NDA (Non-Disclosure Agreement) protects confidentiality, none of which specify hours or detailed scope.
SOWs are fundamental in managing third-party risk and engagements, covered under Security Program Management#6:Chapter 16 CompTIA Security+ Study Guide#.