CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A company's software vendor pushes a routine update to its widely used network monitoring tool. Weeks later, security teams discover the update contained a backdoor inserted by attackers who had compromised the vendor's build server. Which threat vector BEST describes how the organizations were compromised?
- APhishing campaign
- BSupply chain attack
- CInsider threat
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: B. Supply chain attack
Compromising a trusted vendor's build process to distribute malicious code through a legitimate software update is a supply chain attack, which is particularly dangerous because it abuses trusted update mechanisms to reach many downstream customers at once.
Why the other options are wrong
- A. Phishing relies on deceiving individual users into clicking or entering credentials, not compromising a build server.
- C. Insider threat involves a trusted employee acting maliciously, not an external compromise of a vendor.
- D. Brute-force attacks attempt to guess credentials, unrelated to injecting code into a software update.
Supply Chain Attack
An attack that compromises a trusted third-party vendor, supplier, or software update mechanism to distribute malicious code to downstream customers.
- Exploits trust in legitimate vendors/updates
- Can affect many organizations simultaneously
- Mitigated by code signing verification, vendor risk assessments, and SBOM review
Memory trick: Poison the well at the source and everyone downstream drinks it.