What Risk Does Opening Firewall Ports for a SaaS System Introduce?
A technician is opening ports on a firewall for a new system being deployed and supported by a SaaS provider. Which of the following is a risk in the new system?
Community Votes
38% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests recognition that relying on external SaaS providers shifts security control to a third party, creating a supply chain risk rather than just a local configuration issue.
This question evaluates understanding of third-party and supply chain risks when integrating external SaaS solutions into an internal network. Community consensus strongly favors supply chain vendor risk due to the inherent dependency on the SaaS provider's security posture.
Candidates frequently select 'Vulnerable software' because opening ports seems to expose application flaws, but this overlooks the broader architectural dependency on the SaaS vendor's infrastructure and practices highlighted in SY0-701 objectives.
Community Discussion (43 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Third-Party and Supply Chain Risk
The scenario describes a classic third-party dependency situation. In the SY0-701 exam framework, any integration of externally managed services (like SaaS) inherently introduces supply chain risk. By opening firewall ports, the organization is extending trust to the SaaS provider, meaning the security, availability, and compliance of that system now partially depend on the vendor’s internal controls.
Why Option C is Correct
Supply chain vendor risk directly addresses the implications of outsourcing functionality to a SaaS provider. As noted by multiple candidates, the SaaS provider manages the underlying infrastructure, patching schedules, and access controls. If the vendor experiences a breach, implements weak security practices, or faces operational disruptions, your organization inherits those consequences regardless of your local firewall rules. CompTIA consistently maps external service dependencies to supply chain management objectives.
Why the Other Options Are Incorrect
- Default credentials (A) are a local misconfiguration risk. While possible, they are not the primary risk introduced by the SaaS deployment model itself.
- Non-segmented network (B) is a valid architectural concern, but the question specifically emphasizes the SaaS provider context. Without explicit mention of flat network design, segmentation is a secondary consideration compared to the direct vendor dependency.
- Vulnerable software (D) is a tactical risk. While open ports can expose application flaws, CompTIA expects test-takers to prioritize the overarching shared responsibility and third-party risk model when a cloud/SaaS context is explicitly stated. Technical vulnerabilities are a subset of the broader supply chain/vendor risk.
Community Insights & Exam Context
The vote distribution shows a split between C, D, and B, reflecting real-world debate. However, candidates who chose C correctly identified the exam’s preference for high-level risk classification over granular technical symptoms. Commenters like Etc_Shadow28000 and hasquaati highlighted that Layer 3/4 port openings do not equate to Layer 7 software flaws, reinforcing why vendor dependency takes precedence in this scenario.
Official Reference
Exam Strategy
When a SY0-701 question explicitly mentions cloud delivery models (SaaS, PaaS, IaaS) or external vendors, immediately map the scenario to third-party risk, shared responsibility, or supply chain management before analyzing technical controls like firewalls or ACLs. CompTIA tests your ability to recognize organizational and architectural risks over isolated technical misconfigurations.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →