nerdexam
CompTIA

SY0-701 · Question #921

An organization purchases software from an overseas company. The organization's IDS solution detects that advertising data from the software is unexpectedly reporting back to the overseas company. Whi

The correct answer is B. Supply chain. The compromise came through third‐party software the organization obtained and trusted; its unexpected “phone home” behavior is a classic supply chain risk, where embedded code or telemetry from a vendor creates a hidden data exfiltration path.

Submitted by amina.ke· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

An organization purchases software from an overseas company. The organization’s IDS solution detects that advertising data from the software is unexpectedly reporting back to the overseas company. Which of the following threat vectors does this best describe?

Options

  • AEspionage
  • BSupply chain
  • CNation-state
  • DInsider threat

How the community answered

(64 responses)
  • A
    14% (9)
  • B
    78% (50)
  • C
    3% (2)
  • D
    5% (3)

Explanation

The compromise came through third‐party software the organization obtained and trusted; its unexpected “phone home” behavior is a classic supply chain risk, where embedded code or telemetry from a vendor creates a hidden data exfiltration path.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice