A security analyst at an e-commerce firm discovers unauthorized administrative access on an internal transactional database. Investigation reveals that the intruder gained access by compromising an automated software update pipeline managed by an external service contractor trusted by the organization. Which of the following attack vectors was primarily exploited to achieve initial access?
- Supply chainAnswer
- BSpear phishing
- CDirect access
- DWatering hole
Answer
Supply chain attack vector
The correct answer is supply chain because the threat actor targeted a third-party vendor's software deployment infrastructure to bypass internal boundary controls through pre-established trust relationships.
Step-by-Step Solution
Key Concept
Supply Chain Attack Vectors
Estimated Time:1m 15s