SY0-701 exam dumps

SY0-701 practice question 99 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 99

Single answerSupply chain: Service provider , Hardware provider , Software provider

A company is preparing to deploy a new customer relationship management platform that will rely on a cloud-hosted support vendor, laptops from a new hardware manufacturer, and a third-party software package for endpoint management. The security manager wants to reduce supply chain risk before signing contracts and approving deployment. Which action would BEST address supply chain threats across all three provider types?

  1. A

    Require each provider to undergo due diligence that includes security assessments, software integrity validation methods, and verification of hardware provenance and support processes

  2. B

    Rely on the fact that the providers are well-known brands and proceed if they offer the lowest total cost of ownership

  3. C

    Accept the vendors' standard contracts as long as they state that security is the customer's responsibility after delivery

  4. D

    Focus only on vulnerability scanning after deployment, since supply chain risk cannot be meaningfully reduced before implementation

Show answer and explanation

Correct answer: A

Explanation

The best answer is the option that applies formal supply chain risk management across service providers, hardware providers, and software providers before deployment. In Security+ terms, organizations should perform vendor assessment and due diligence, verify hardware source and authenticity, and validate software integrity and update mechanisms. This aligns with broadly accepted best practices from NIST, including supply chain risk management guidance in NIST SP 800-161 and software integrity concepts emphasized in secure development and code-signing practices. Real-world supply chain defense is layered: contractual requirements, vendor reviews, provenance checks, trusted sourcing, software signing validation, and ongoing monitoring all play a role. The other options reflect common but weak approaches: trusting brand reputation, relying on boilerplate contracts, or delaying security review until after implementation.

  • A. Correct.

    Correct. Supply chain risk management should include vendor due diligence before procurement and deployment. For a service provider, this means reviewing security controls, incident response commitments, and support processes. For a hardware provider, it includes verifying provenance, chain of custody, authorized distributors, and authenticity of components to reduce the risk of counterfeit or tampered devices. For a software provider, it includes validating software integrity through signed code, trusted repositories, update mechanisms, and secure development practices. This is the most comprehensive response because it addresses service, hardware, and software supply chain concerns before the organization assumes operational risk.

  • B. Incorrect.

    Incorrect. Brand recognition and low cost do not meaningfully mitigate supply chain risk. Well-known vendors can still be affected by compromise, counterfeit distribution channels, insecure subcontractors, or weak update processes. Choosing providers primarily on cost is a common procurement mistake that ignores risk management requirements.

  • C. Incorrect.

    Incorrect. Standard contracts that shift security responsibility to the customer do not reduce supplier-originated risk. Organizations should negotiate security requirements such as breach notification timelines, audit rights, service-level expectations, support escalation paths, and assurances around hardware authenticity and software update integrity. Simply accepting liability language leaves the organization exposed.

  • D. Incorrect.

    Incorrect. Vulnerability scanning after deployment is useful, but it is not sufficient and does not replace pre-acquisition supply chain controls. Some supply chain issues, such as counterfeit hardware, malicious firmware, insecure vendor support practices, or compromised software build pipelines, may not be fully detected by routine scanning after implementation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam