Study. uk . com
  1. Home
  2. All questions
  3. Question 170

CompTIA Security+ study material · question 170 of 611

Why do supply chain vulnerabilities defeat controls aimed at untrusted input?

  1. They arrive encrypted and cannot be inspected
  2. They only affect hardware
  3. They reach the organisation through a trusted channel such as a signed update
  4. They are never assigned a CVE identifier
Show the answer

Answer: C. They reach the organisation through a trusted channel such as a signed update

The delivery path is one the organisation has deliberately chosen to trust, so untrusted-input controls never see it.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Abstract

Challenge yourself on this topic → Study as cards