What Type of Vulnerability Involves a Malicious Software Update?
A malicious update was distributed to a common software platform and disabled services at many organizations. Which of the following best describes this type of vulnerability?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests recognition of supply chain attacks, which exploit trust in software vendors and updates, and the common trap is confusing them with insider threats because the attacker may be inside the vendor.
A malicious update distributed to a widely used software platform that disables services across many organizations is a supply chain vulnerability. Community consensus identifies this as a supply chain attack, distinguishing it from insider threats or DDoS attacks.
Choosing 'insider threat' because the malicious actor may be an employee of the software vendor, but the vulnerability is in the software distribution mechanism, not an individual's actions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Supply chain attacks occur when an attacker compromises a trusted third-party software vendor and distributes malicious code through legitimate update channels. This matches the scenario where a single malicious update to a common software platform affects many organizations simultaneously. As comment [2] notes, this highlights risks associated with third-party software and dependencies. Comment [1] correctly compares it to the recent CrowdStrike Falcon update incident, a real-world example of a supply chain disruption.Why the Other Options Are Wrong
A DDoS attack is a distributed denial-of-service attack that overwhelms a service with traffic, not a malicious software update. Rogue employee and insider threat both refer to threats originating from within an organization, typically from employees or contractors, whereas a supply chain attack involves an external dependency or vendor. The key is that the vulnerability lies in the software supply chain, not in the victim organization's internal personnel or network infrastructure.Community Comment Notes
Comments consistently support answer D. Comment [2] explains that this type of vulnerability occurs when a malicious update affects software that many organizations rely on, emphasizing the supply chain dependency. Comment [3] provides a clear definition: supply chain attacks exploit vulnerabilities in the network of trusted vendors or suppliers, often through malicious code injection or software updates, aiming for data theft, sabotage, or ransomware. These comments reinforce why the correct answer is unequivocally 'Supply chain.'Official Reference
Exam Strategy
When you see 'malicious update' and 'many organizations' in the question, immediately consider supply chain attacks. Pay close attention to whether the threat actor is internal to the victim (insider threat) or external but trusted via a vendor relationship — the latter is the supply chain indicator.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →