A technician is opening ports on a firewall for a new system being deployed and supported by a SaaS provider. Which of the following is a risk in the new system?
Choose an answer
Tap an option to check your answer.
Correct answer: Supply chain vendor.
Why this is the answer
The correct answer is Supply chain vendor. When integrating a new system supported by a SaaS provider, the organization becomes reliant on the security practices and integrity of that third-party vendor. This introduces supply chain risk, as vulnerabilities or breaches within the SaaS provider's infrastructure could directly impact the organization. Default credentials are a common vulnerability but are typically an internal configuration issue, not an inherent risk of the new system itself from a SaaS provider. A non-segmented network is an internal network architecture problem, not directly caused by the new SaaS system. Vulnerable software is a general risk, but the specific risk highlighted by the scenario of integrating a SaaS provider's system is the dependency on an external entity (the supply chain vendor).
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed