CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A company's software vendor pushes a routine update to its widely used network monitoring tool. Weeks later, security teams discover the update contained a backdoor inserted by attackers who had compromised the vendor's build server. Which threat vector BEST describes how the organizations were compromised?

  1. APhishing campaign
  2. BSupply chain attack
  3. CInsider threat
  4. DBrute-force attack
Show answer & explanation

Correct answer: B. Supply chain attack

Compromising a trusted vendor's build process to distribute malicious code through a legitimate software update is a supply chain attack, which is particularly dangerous because it abuses trusted update mechanisms to reach many downstream customers at once.

Why the other options are wrong

  • A. Phishing relies on deceiving individual users into clicking or entering credentials, not compromising a build server.
  • C. Insider threat involves a trusted employee acting maliciously, not an external compromise of a vendor.
  • D. Brute-force attacks attempt to guess credentials, unrelated to injecting code into a software update.

Supply Chain Attack

An attack that compromises a trusted third-party vendor, supplier, or software update mechanism to distribute malicious code to downstream customers.

  • Exploits trust in legitimate vendors/updates
  • Can affect many organizations simultaneously
  • Mitigated by code signing verification, vendor risk assessments, and SBOM review

Memory trick: Poison the well at the source and everyone downstream drinks it.

More Threats, Vulnerabilities, and Mitigations questions