Study. uk . com
  1. Home
  2. All questions
  3. Question 83

CompTIA Security+ study material · question 83 of 611

A supplier passed its assessment two years ago and has not been reviewed since. What risk does this create?

  1. The contract automatically renews at a higher price
  2. Degradation in the supplier's posture goes undetected
  3. The original assessment becomes legally void
  4. Fourth-party suppliers are added without notice
Show the answer

Answer: B. Degradation in the supplier's posture goes undetected

Third-party risk does not end at onboarding; only continuous monitoring catches a vendor that weakens after signature.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Supplier Relationships

Challenge yourself on this topic → Study as cards