CompTIA Security+ (SY0-701)Security Program Management and OversightHard
A manufacturer relies on a single overseas supplier for a critical microchip used in its flagship product. A geopolitical event disrupts the supplier's shipments, halting production for three months. Which type of risk does this scenario best illustrate?
- ASupply chain risk
- BOperational risk from insider threats
- CRegulatory compliance risk
- DResidual risk
Show answer & explanationAnswer & explanation
Correct answer: A. Supply chain risk
Supply chain risk arises from dependency on external suppliers, vendors, or partners whose disruptions, failures, or geopolitical exposure can materially affect an organization's operations, as illustrated by the sole-source overseas supplier disruption.
Why the other options are wrong
- B. Insider threat risk involves malicious or negligent actions by internal personnel, not external supplier disruption.
- C. Regulatory compliance risk relates to failure to meet legal/regulatory requirements, not supplier disruption.
- D. Residual risk is the risk remaining after controls are applied, not the description of a supplier dependency event.
Supply Chain Risk
The risk that disruptions, failures, or compromises within an organization's supplier or vendor network will adversely affect its operations, products, or security.
- Often heightened by single-source or sole-supplier dependencies
- Includes geopolitical, financial, and cybersecurity risks from third parties
- Mitigated through vendor diversification, due diligence, and contractual controls
Memory trick: One supplier, one point of failure—diversify the chain