A security analyst at an e-commerce firm discovers unauthorized administrative access on an internal transactional database. Investigation reveals that the intruder gained access by compromising an automated software update pipeline managed by an external service contractor trusted by the organization. Which of the following attack vectors was primarily exploited to achieve initial access?
- Supply chainCevap
- BSpear phishing
- CDirect access
- DWatering hole
Cevap
Supply chain attack vector
The correct answer is supply chain because the threat actor targeted a third-party vendor's software deployment infrastructure to bypass internal boundary controls through pre-established trust relationships.
Adım Adım Çözüm
Anahtar Kavram
Supply Chain Attack Vectors
Tahmini Süre:1m 15s