A contractor is required to visually inspect the motherboards of all new servers that are purchased to determine whether the servers were tampered with. Which of the following risks is the contractor attempting to mitigate?
Choose an answer
Tap an option to check your answer.
Correct answer: Supply chain.
Why this is the answer
The contractor is attempting to mitigate a supply chain risk. Supply chain attacks involve malicious actors introducing vulnerabilities or tampering with hardware or software at any point during the product's lifecycle, from manufacturing to delivery. Visually inspecting motherboards for signs of tampering (e.g., unauthorized components, altered circuits) is a direct measure against such an attack, where hardware could be compromised before it reaches the organization. An embedded rootkit is a type of malware, but the visual inspection is aimed at detecting physical hardware alterations that could facilitate a rootkit, not the rootkit itself. Firmware failure relates to software issues within the device's firmware, not physical tampering. An RFID keylogger is a specific type of eavesdropping device, which might be part of a supply chain attack but is not the overarching risk being mitigated by a general visual inspection for tampering.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed