Threats & AttacksQuestion 14 of 100
Which term describes a hidden vulnerability in a third-party component that compromises everyone who uses it?
a.Supply chain risk
b.Insider risk
c.Physical risk
d.Configuration drift
Explanation
Supply chain risk arises when a trusted vendor, library, or hardware component is compromised, affecting downstream customers. A single tainted update can reach many organizations. Vendor assessments and software bill of materials help manage this risk.
Practice all 100 questions free — no signup required.
Related questions on this topic
- A malicious program spreads across a network automatically without any user interaction. What is it?
- An attacker calls an employee pretending to be IT support to trick them into revealing a password. This voice-based social engineering is called:
- Which attack compromises a website frequently visited by a target group to infect their systems?
- Malware that records every keystroke a user types to capture passwords is a:
- An attacker registers a domain like 'goggle.com' hoping users mistype the real address. This is:
- Which type of malware hides deep in the operating system to conceal its presence and maintain privileged access?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against CompTIA Security+ (SY0-701) · How we review