How to Mitigate Counterfeit Hardware Risks During Procurement?
A company is required to use certified hardware when building networks. Which of the following best addresses the risks associated with procuring counterfeit hardware?
Community Votes
77% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the critical distinction between proactive due diligence during the sourcing phase versus reactive post-delivery controls, with the primary trap being the intuitive but incorrect appeal of audit clauses.
This question evaluates proactive supply chain risk management strategies to prevent counterfeit hardware from entering an organization. The overwhelming community consensus emphasizes that pre-procurement analysis is superior to reactive contractual measures or static policies.
Candidates often select Option C (right to audit clause), mistaking contractual enforcement for immediate verification. In reality, audit clauses are typically invoked after goods are delivered, making them reactive/detective rather than preventative, which contradicts the question's focus on the 'procuring' phase.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer: Proactive Supply Chain Analysis
Option A is correct because mitigating counterfeit hardware risks requires proactive due diligence during the procurement lifecycle. Conducting a thorough analysis of the supply chain allows organizations to verify supplier legitimacy, assess manufacturing origins, validate certifications, and identify potential tampering points before committing to a purchase. This aligns with CompTIA’s emphasis on Supply Chain Risk Management (SCRM), which prioritizes preventing compromised assets from entering the environment over detecting them afterward.Why Other Options Fall Short
- Option B (Corporate acquisition policy) establishes internal rules but lacks an active verification mechanism. Policies dictate behavior but do not inherently authenticate hardware or vet external vendors.
- Option C (Right to audit clause) is a strong distractor. While valuable for long-term compliance, audit rights are primarily invoked after transactions occur or during scheduled reviews. As noted by multiple community members, audits are reactive controls; they help detect issues post-delivery but do not stop counterfeit items during initial procurement.
- Option D (Penetration testing) assesses network or system security vulnerabilities, not physical supply chain integrity or hardware authenticity. Pen testing cannot detect counterfeit components or verify manufacturing provenance.
Community Insights & Exam Nuances
The SY0-701 exam frequently tests the preventive vs. detective control distinction. Several candidates highlighted that while audit clauses enable future verification, they do not address the immediate risk at the sourcing stage. Others pointed out that "thorough analysis" encompasses vendor assessment, background checks, and certification validation, directly satisfying the requirement for certified hardware. When you see keywords like "procuring," "sourcing," or "building," prioritize pre-implementation analysis over post-deployment monitoring or contractual language.Official Reference
https://www.nist.gov/publications/cybersecurity-supply-chain-risk-management-practices-systems-and-organizations-sp-800-161 https://a.compTia.org/Resources/Exam-Syllabus/SY0-701-CompTIA-Security-Exam-Versions https://www.iso.org/standard/45260.htmlExam Strategy
Always map the question's timeline to the type of control needed. Keywords like "procuring," "sourcing," or "planning" signal a need for preventive actions (e.g., analysis, vetting, design), while terms like "after deployment," "post-incident," or "ongoing compliance" point toward detective or corrective measures (e.g., audits, logging, patching). When unsure between analysis/vetting and contractual clauses, remember that CompTIA favors proactive technical/process verification over legal/administrative frameworks for physical asset authenticity.Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →