Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A company is reviewing its security posture after a competitor suffered a data breach due to a compromised third-party vendor. The company wants to evaluate the potential risks associated with its own suppliers, partners, and cloud service providers. Which cybersecurity concept are they focusing on?

  1. AInsider Threat
  2. BSupply Chain Attack
  3. CDenial of Service (DoS)
  4. DSocial Engineering
Show answer & explanation

Correct answer: B. Supply Chain Attack

The scenario describes a concern related to third-party vendors and their potential to introduce vulnerabilities or serve as an attack vector, which is precisely the definition of a supply chain attack.

Why the other options are wrong

  • A. An insider threat originates from within the organization, not from external vendors.
  • C. DoS attacks aim to make services unavailable, unrelated to third-party vendor compromise leading to data breach.
  • D. Social engineering manipulates individuals, not specifically focusing on third-party vendor relationships.

Supply Chain Attack

A cyberattack that targets an organization by compromising less secure elements in its supply chain, such as third-party vendors, software providers, or hardware manufacturers.

  • Exploits trust relationships.
  • Can affect many downstream customers.
  • Difficult to detect and prevent.

Memory trick: A chain is only as strong as its weakest link, especially when it's your vendor.

More Cybersecurity Fundamentals questions