A malicious update was distributed to a common software platform and disabled services at many organizations. Which of the following best describes this type of vulnerability?
Choose an answer
Tap an option to check your answer.
Correct answer: Supply chain.
Why this is the answer
A supply chain attack occurs when an adversary infiltrates an organization by targeting less secure elements in its supply chain. In this scenario, the malicious update to a common software platform, which then affected many organizations, is a classic example of a supply chain attack. The attacker compromised the software vendor (a link in the supply chain) to distribute malware to its customers. DDoS (Distributed Denial of Service) is an attack that overwhelms a system with traffic, not the distribution of malicious software. A rogue employee is an insider threat, but the question describes a malicious update to a common software platform, implying an external compromise of a vendor, not an internal employee of the affected organizations. While an insider threat can be a rogue employee, the scope here is broader, affecting multiple organizations through a shared vendor.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed