nerdexam
CompTIA

SY0-701 · Question #153

Which of the following are the most likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two).

The correct answer is D. Included third-party libraries E. Vendors/supply chain. Software that is outsourced to vendors and third parties is vulnerable to malware being injected into the product from the supply chain.

Submitted by viktor_hu· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

Which of the following are the most likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two).

Options

  • ACertificate mismatch
  • BUse of penetration-testing utilities
  • CWeak passwords
  • DIncluded third-party libraries
  • EVendors/supply chain
  • FOutdated anti-malware software

How the community answered

(29 responses)
  • B
    7% (2)
  • C
    3% (1)
  • D
    76% (22)
  • F
    14% (4)

Explanation

Software that is outsourced to vendors and third parties is vulnerable to malware being injected into the product from the supply chain.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice