How to Mitigate Counterfeit Hardware Risks During Procurement?

A company is required to use certified hardware when building networks. Which of the following best addresses the risks associated with procuring counterfeit hardware?

  1. A thorough analysis of the supply chain Source Reference Answer
  2. A legally enforceable corporate acquisition policy
  3. A right to audit clause in vendor contracts and SOWs
  4. An in-depth penetration test of all suppliers and vendors

Community Votes

A
77%
C
23%

77% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the critical distinction between proactive due diligence during the sourcing phase versus reactive post-delivery controls, with the primary trap being the intuitive but incorrect appeal of audit clauses.

This question evaluates proactive supply chain risk management strategies to prevent counterfeit hardware from entering an organization. The overwhelming community consensus emphasizes that pre-procurement analysis is superior to reactive contractual measures or static policies.

Candidates often select Option C (right to audit clause), mistaking contractual enforcement for immediate verification. In reality, audit clauses are typically invoked after goods are delivered, making them reactive/detective rather than preventative, which contradicts the question's focus on the 'procuring' phase.

Community Discussion (18 comments)

Mehsotopes 👍 11 Selected: A
An analysis would safely address if their was a lack of reliability, or authenticity when procuring hardware from a supplier to protect the company.
Mehsotopes 👍 7 Selected: A
A penetration test would be checking the security practices of your supply chain to ensure they are not easily tampered with, but does not address the lack of reliability, & authenticity that would protect a company from the possible procurement of faulty supplies/hardware like an analysis would. An enforced acquisition policy would be a bad practice especially if the parts were faulty. A right to audit clause, & Statement of Work (SOW) is the first step to allowing an analysis, or penetration test of vendor services, & goods.
IT_dude_in_training 👍 1 Selected: A
A. A thorough analysis of the supply chain. When a company is required to use certified hardware, the integrity of the supply chain is critical. Conducting a thorough analysis of the supply chain ensures that hardware is sourced from trusted and verified suppliers. Why not B. A legally enforceable corporate acquisition policy: While this policy can set expectations, it doesn't actively verify the legitimacy of the hardware before purchase.?
Samuel07 👍 1 Selected: C
A right to audit clause, ensure that you have control over what is being supplied and not just rely on supplier previous record.
JackExam2025 👍 1
Thorough analysis of the supply chain is the best approach to mitigate the risks associated with procuring counterfeit hardware. It focuses on ensuring that hardware is sourced from legitimate, certified vendors and suppliers.
Leek23 👍 1 Selected: A
A. A thorough analysis of the supply chain A thorough analysis of the supply chain helps identify and mitigate risks related to counterfeit hardware. By assessing the origin and authenticity of hardware components, verifying suppliers, and ensuring compliance with standards, the company can reduce the chances of receiving counterfeit or substandard hardware. While the other options might be useful in different contexts, supply chain analysis specifically addresses the issue of procuring counterfeit hardware.
Midos 👍 1 Selected: C
The best answer to the question is C: A right to audit clause in vendor contracts and SOWs. Here's why: Option C: This option ensures that the company has the legal right to inspect the hardware and its supply chain, which can help mitigate the risks associated with procuring counterfeit hardware. It provides a contractual obligation for the vendor to allow audits, ensuring that the company can verify the authenticity of the hardware before deployment. While options A and B are also valid practices for managing supply chain risks, they do not directly address the specific risk of procuring counterfeit hardware. Option D is an excellent practice for identifying vulnerabilities in a network, but it does not specifically address the issue of counterfeit hardware. In summary, having the legal right to audit vendors and their supply chains is the most direct and effective way to address the risks associated with procuring counterfeit hardware.
babujiju 👍 1 Selected: A
The company should implement a supply chain risk management (SCRM) program.
atta_papa23 👍 1 Selected: A
In the process of conducting due diligence, companies can request for (external) audits which will fall under the right to audit clause. Right to audit clause is not only after the fact
41c27e6 👍 2 Selected: A
I was about to say C, although correct answer is A - bcoz audit is AFTER the transaction. We want to investigate first, before buying anything from the suplier.
Bito808 👍 1
I think the key word is "procuring". This involves getting quotes from vendors. Some requirements may only allow components and manufacturing from US based vendors. That's where you need to be mindful of the supply chain. Case example - some brands were found to be beaconing information to foreign countries.
User92 👍 3 Selected: A
While "C" is a valuable measure, it primarily ensures compliance and accountability after the fact. It allows for the detection of issues during audits but doesn’t proactively prevent counterfeit hardware from entering the supply chain. "A" is a more proactive approach. It involves evaluating and monitoring the entire supply chain to identify and mitigate risks before counterfeit hardware can be procured. So, it should be "A" - correct answer.
3330278_111 👍 3 Selected: C
I did a lot of back and forth with ChatGPT regarding this topic, and even brought up some of the points people were making here. The first response it got was also A. But after discussing what both options (A & C) can offer as a solution to this problem, it eventually changed it's mind to C. To me C makes most sense as it provides an actionable solution that provides direct control
nap61 👍 1 Selected: C
You cannot do a thorough analysis of the supply chain without a right to audit. ;-) Also, a right to audit will be fundamental to separate the supplier that allow (and become a supplier) from those one that would not allow auditing (and not become a supplier).
tamdod 👍 2
Trick question? Is Assessment the same as analysis as far as Comptia is concerned? Vendor assessment is a thorough background check for potential suppliers that allows an organization to gauge their due diligence, competence, and dependability for the safeguarding of business interests and stringent quality control.
dbrowndiver 👍 3 Selected: C
Vendor Accountability: By including a right to audit clause, the company ensures vendors are accountable for providing certified hardware. This clause can serve as a deterrent against the supply of counterfeit products, as vendors know their processes and products can be reviewed at any time. Verification of Authenticity: Audits can include checks on the supply chain processes, manufacturing practices, and documentation related to the origin and certification of hardware. This ensures that only legitimate products are used in network construction. Just saying...
Zach123654 👍 2
I could see A or C. I'm leaning towards A.
Mehsotopes 👍 4 Selected: A
A penetration test would be checking the security practices of your supply chain to ensure they are not easily tampered with, but does not address the lack of reliability, & authenticity that would reason for the procurement of faulty supplies (hardware) like an analysis would. An enforced acquisition policy would be a bad practice especially if the parts were faulty. A right to audit clause, & Statement of Work (SOW) is the first step to allowing an analysis, or penetration test of vendor services, & goods.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Correct Answer: Proactive Supply Chain Analysis

Option A is correct because mitigating counterfeit hardware risks requires proactive due diligence during the procurement lifecycle. Conducting a thorough analysis of the supply chain allows organizations to verify supplier legitimacy, assess manufacturing origins, validate certifications, and identify potential tampering points before committing to a purchase. This aligns with CompTIA’s emphasis on Supply Chain Risk Management (SCRM), which prioritizes preventing compromised assets from entering the environment over detecting them afterward.

Why Other Options Fall Short

  • Option B (Corporate acquisition policy) establishes internal rules but lacks an active verification mechanism. Policies dictate behavior but do not inherently authenticate hardware or vet external vendors.
  • Option C (Right to audit clause) is a strong distractor. While valuable for long-term compliance, audit rights are primarily invoked after transactions occur or during scheduled reviews. As noted by multiple community members, audits are reactive controls; they help detect issues post-delivery but do not stop counterfeit items during initial procurement.
  • Option D (Penetration testing) assesses network or system security vulnerabilities, not physical supply chain integrity or hardware authenticity. Pen testing cannot detect counterfeit components or verify manufacturing provenance.

Community Insights & Exam Nuances

The SY0-701 exam frequently tests the preventive vs. detective control distinction. Several candidates highlighted that while audit clauses enable future verification, they do not address the immediate risk at the sourcing stage. Others pointed out that "thorough analysis" encompasses vendor assessment, background checks, and certification validation, directly satisfying the requirement for certified hardware. When you see keywords like "procuring," "sourcing," or "building," prioritize pre-implementation analysis over post-deployment monitoring or contractual language.

Official Reference

https://www.nist.gov/publications/cybersecurity-supply-chain-risk-management-practices-systems-and-organizations-sp-800-161 https://a.compTia.org/Resources/Exam-Syllabus/SY0-701-CompTIA-Security-Exam-Versions https://www.iso.org/standard/45260.html

Exam Strategy

Always map the question's timeline to the type of control needed. Keywords like "procuring," "sourcing," or "planning" signal a need for preventive actions (e.g., analysis, vetting, design), while terms like "after deployment," "post-incident," or "ongoing compliance" point toward detective or corrective measures (e.g., audits, logging, patching). When unsure between analysis/vetting and contractual clauses, remember that CompTIA favors proactive technical/process verification over legal/administrative frameworks for physical asset authenticity.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide