- Home
- All questions
- Question 83
CompTIA Security+ study material · question 83 of 611
A supplier passed its assessment two years ago and has not been reviewed since. What risk does this create?
Show the answer
Answer: B. Degradation in the supplier's posture goes undetected
Third-party risk does not end at onboarding; only continuous monitoring catches a vendor that weakens after signature.
Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Supplier Relationships