CompTIA
SY0-701 · Question #153
Which of the following are the most likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two).
The correct answer is D. Included third-party libraries E. Vendors/supply chain. Software that is outsourced to vendors and third parties is vulnerable to malware being injected into the product from the supply chain.
Submitted by viktor_hu· Mar 6, 2026Threats, vulnerabilities, and mitigations
Question
Which of the following are the most likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two).
Options
- ACertificate mismatch
- BUse of penetration-testing utilities
- CWeak passwords
- DIncluded third-party libraries
- EVendors/supply chain
- FOutdated anti-malware software
How the community answered
(29 responses)- B7% (2)
- C3% (1)
- D76% (22)
- F14% (4)
Explanation
Software that is outsourced to vendors and third parties is vulnerable to malware being injected into the product from the supply chain.
Community Discussion
No community discussion yet for this question.