What Tool Provides Full-Spectrum Supply Chain Analysis?
An organization requests a third-party full-spectrum analysis of its supply chain. Which of the following would the analysis team use to meet this requirement?
Community Votes
70% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to differentiate between supply chain risk management platforms and technical security protocols, with the primary trap being acronym misinterpretation.
This question evaluates understanding of comprehensive supply chain risk assessment methods, with strong community consensus pointing to illumination tools for holistic visibility. Candidates must distinguish between broad supply chain mapping and narrow cybersecurity automation frameworks.
Many candidates incorrectly select SCAP, mistakenly expanding it as 'Supply Chain Assessment Process' instead of recognizing it as Security Content Automation Protocol, which is strictly designed for automating vulnerability and compliance checks rather than end-to-end supply chain visualization.
Community Discussion (20 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Supply Chain Illumination
An illumination tool is specifically engineered to provide third-party organizations with a comprehensive, full-spectrum view of a supply chain. These platforms map dependencies, assess financial and reputational risks, verify beneficial ownership, and identify potential points of failure across multiple tiers of vendors and partners. As highlighted by community members, these tools deliver the holistic visibility required for modern supply chain risk management (SCRM) beyond mere technical security checks [4][8][15].Why SCAP Is a Distractor
The most frequent incorrect choice is SCAP. In the CompTIA Security+ curriculum and industry standards, SCAP unequivocally stands for Security Content Automation Protocol, a NIST-backed framework used to automate vulnerability detection, configuration management, and compliance reporting [13]. While highly valuable for patch management and technical audits, SCAP does not evaluate business continuity, vendor financial health, or multi-tier logistical dependencies. Several candidates fell into the trap of assuming SCAP meant "Supply Chain Assessment Process," which is not a recognized industry standard [14].Evaluating the Remaining Options
A vulnerability scanner (Option A) and a penetration test (Option B) are both reactive or proactive technical security assessments focused on identifying exploitable flaws in networks, applications, or infrastructure. They lack the breadth required for a "full-spectrum" organizational analysis. The question explicitly requests a third-party evaluation of the entire supply chain ecosystem, making illumination tools the only option that aligns with SY0-701 objectives for third-party risk assessment and vendor due diligence.Official Reference
Exam Strategy
When faced with acronyms on the SY0-701 exam, always default to their officially defined CompTIA or NIST meanings rather than guessing based on context clues. If a seemingly logical expansion contradicts established cybersecurity standards, eliminate it immediately and focus on broader risk management terminology that matches the scenario's scope.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →