Study. uk . com
  1. Home
  2. All questions
  3. Question 84

CompTIA Security+ study material · question 84 of 611

An organisation's SaaS provider depends on a third-party payment processor that the organisation has never assessed. What is this exposure called?

  1. Fourth-party risk
  2. Residual risk
  3. Shadow IT
  4. Inherent risk
Show the answer

Answer: A. Fourth-party risk

Fourth-party risk comes from a supplier's own suppliers, and is invisible unless the contract requires disclosure of dependencies.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Supply Chain

Challenge yourself on this topic → Study as cards