SY0-701 exam dumps

SY0-701 practice question 98 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 98

Single answerSupply chain: Service provider , Hardware provider , Software provider

A company is preparing to deploy 500 point-of-sale terminals across multiple retail locations. The devices will be purchased from a hardware manufacturer, managed remotely by a third-party service provider, and loaded with payment software from an external software vendor. Security leadership is concerned about supply chain risk before deployment. Which action would BEST reduce the risk of introducing compromised components from these providers while still allowing the rollout to proceed on schedule?

  1. A

    Require each provider to submit a signed attestation of security practices, and rely on those statements as the primary validation before deployment

  2. B

    Perform acceptance testing that validates hardware authenticity, verifies software signatures and hashes, and reviews the service provider's access controls and contractual security requirements before production use

  3. C

    Delay the deployment until all providers can prove they have never experienced a security incident or third-party compromise

  4. D

    Allow the service provider to install and configure all systems directly in production so any issues can be identified through live monitoring after rollout

Show answer and explanation

Correct answer: B

Explanation

The best answer is the option that applies supply chain risk management across all three provider types: hardware, software, and service. In practice, organizations should perform vendor due diligence and also verify what they actually receive before it is trusted in production. For hardware providers, this can include confirming chain of custody, serial numbers, trusted platform or firmware status, and signs of tampering or counterfeiting. For software providers, organizations should validate digital signatures, checksums or hashes, and software provenance before installation. For service providers, organizations should review contractual security requirements, remote access restrictions, MFA usage, logging, segmentation, and least-privilege administration. This aligns with widely accepted best practices from NIST guidance on supply chain risk management and software integrity, including concepts found in NIST SP 800-161 for cyber supply chain risk management and NIST SP 800-218 SSDF for secure software development and software integrity verification. The key exam takeaway is that supply chain risk is best reduced through independent verification and formal acceptance controls, not by trust alone or by waiting to detect problems after deployment.

  • A. Incorrect.

    This is insufficient as the primary control. Vendor attestations and questionnaires are useful for due diligence, but they do not independently verify that delivered hardware, software, or services are trustworthy. A signed statement alone would not detect counterfeit hardware, tampered firmware, malicious software updates, or weak remote administration practices.

  • B. Correct.

    This is correct. A layered acceptance process is the most effective practical response to supply chain risk across hardware, software, and service providers. Validating hardware authenticity helps detect counterfeit or unauthorized components. Verifying software signatures and hashes helps confirm integrity and publisher legitimacy. Reviewing the service provider's access model, least-privilege controls, logging, and contractual obligations helps reduce the risk introduced by outsourced administration. This approach is both realistic and aligned with standard procurement and deployment practices.

  • C. Incorrect.

    This is incorrect because it sets an unrealistic and unnecessary condition. Even mature providers may experience security incidents. The goal of supply chain risk management is to assess, verify, and mitigate risk through controls, not to require a provider to prove a perfect history. Candidates may choose this because it sounds strict, but it is not operationally practical or consistent with risk-based security management.

  • D. Incorrect.

    This is incorrect because it shifts validation until after production exposure. Live monitoring is valuable, but it is a detective control, not a substitute for pre-deployment verification. Allowing a third party to install systems directly into production without prior validation increases the chance that compromised hardware, malicious software, or overly permissive remote access could affect business operations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam