nerdexam
Palo_Alto_Networks

PCDRA · Question #78

How does an attacker prefer to carry out supply-chain attacks?

The correct answer is B. By targeting employees (software developers) of the target organization. Attackers prefer to execute supply-chain attacks by compromising employees, particularly software developers, of a target organization to inject malicious code into legitimate products.

Submitted by rohit_dlh· Apr 18, 2026Threat Hunting

Question

How does an attacker prefer to carry out supply-chain attacks?

Options

  • ABy targeting an organization directly through phishing or exploitation of vulnerabilities
  • BBy targeting employees (software developers) of the target organization
  • CBy targeting items that aren't written to disk
  • DBy targeting an organization's upper management directly

How the community answered

(24 responses)
  • B
    92% (22)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Attackers prefer to execute supply-chain attacks by compromising employees, particularly software developers, of a target organization to inject malicious code into legitimate products.

ABy targeting an organization directly through phishing or exploitation of vulnerabilities

Targeting an organization directly through phishing or exploiting vulnerabilities is a direct attack, not specifically a supply-chain attack which leverages a trusted third party.

BBy targeting employees (software developers) of the target organizationCorrect

A common method for supply-chain attacks involves compromising individuals within a software vendor or supplier organization, such as software developers, to gain access to their development environment and inject malicious code into legitimate software. This allows the malware to be distributed covertly through trusted channels.

CBy targeting items that aren't written to disk

Targeting items not written to disk (fileless malware) is a technique, but it's not the method of carrying out a supply-chain attack; it's a characteristic of some payloads.

DBy targeting an organization's upper management directly

While upper management can be targets, compromising software developers or those with access to product development is more aligned with the goal of injecting malicious code into the supply chain itself.

Concept tested: Supply chain attack vectors

Source: https://www.cisa.gov/news-events/news/cisa-insight-defending-against-supply-chain-attacks

Topics

#Supply-chain attacks#Attack vectors#Software development security#Threat actor tactics

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice