220-1102 exam dumps

220-1102 practice question 453 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 453

Single answerSupply chain/pipeline attack

A small business uses a widely trusted remote monitoring and management (RMM) tool to push updates and scripts to all company workstations. After a routine vendor update, several PCs begin making outbound connections to unfamiliar internet hosts, even though the users did not install anything new. The IT technician confirms the activity started shortly after the signed update was deployed through the RMM platform. Which of the following best describes this type of attack?

  1. A

    A supply chain attack, because a trusted vendor or update channel was compromised and used to distribute malicious code

  2. B

    A phishing attack, because users were tricked into clicking a malicious link in email

  3. C

    A brute-force attack, because attackers guessed local administrator passwords on multiple PCs

  4. D

    A denial-of-service attack, because the update caused network congestion from too many connections

Show answer and explanation

Correct answer: A

Explanation

The best answer is the supply chain attack. On A+ Core 2, this concept refers to an attacker compromising a vendor, service provider, software repository, managed services platform, or update mechanism so malicious content is delivered through a trusted relationship. In real environments, this can occur through compromised software builds, poisoned updates, or abused remote management tools. A technician should recognize the indicators: trusted software, broad impact across multiple systems, and malicious behavior beginning immediately after a legitimate deployment. Best practices include validating vendor security advisories, restricting administrative/update channels, monitoring endpoint and network behavior after updates, using application allowlisting where appropriate, and following incident response procedures such as isolating affected systems and reviewing trusted software sources. This aligns with standard security guidance from organizations such as CISA and NIST regarding software supply chain risk management and incident handling.

  • A. Correct.

    Correct. This is the classic pattern of a supply chain or pipeline attack: attackers compromise a trusted third party, software provider, or update mechanism and then use that legitimate distribution path to push malicious code to downstream customers. The key clues are that the software was trusted, the update was signed, and multiple systems were affected immediately after deployment through a centralized management platform.

  • B. Incorrect.

    Incorrect. Phishing typically involves deceiving users into opening attachments, entering credentials, or clicking malicious links. In this scenario, there is no indication that end users interacted with email or were socially engineered. The malicious activity began after a vendor update was automatically deployed through a legitimate tool.

  • C. Incorrect.

    Incorrect. A brute-force attack involves repeated attempts to guess passwords or authentication secrets. While attackers may use stolen or weak credentials in some breaches, the scenario specifically points to a compromised software update path, not password guessing against endpoints.

  • D. Incorrect.

    Incorrect. A denial-of-service attack focuses on reducing availability by overwhelming systems or networks. Although the infected PCs are making many outbound connections, the primary issue described is malicious code being delivered through a trusted update channel, which aligns with a supply chain attack rather than a DoS event.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam