exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 48 discussion

Actual exam question from CompTIA's SY0-601
Question #: 48
Topic #: 1
[All SY0-601 Questions]

Which of the following is the GREATEST security concern when outsourcing code development to third-party contractors for an internet-facing application?

  • A. Intellectual property theft
  • B. Elevated privileges
  • C. Unknown backdoor
  • D. Quality assurance
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
varun0
Highly Voted 2 years, 8 months ago
Selected Answer: C
GREATEST security concern would be unknown backdoor
upvoted 17 times
...
Ay_ma
Highly Voted 2 years, 8 months ago
A- Intellectual Property Theft: I'm guessing by that point a legal contract is already on ground to mitigate such an issue. Unknown Backdoor, in my opinion, is equivalent to a zero-day attack. You have no idea if these contractors knowingly or unknowingly but a backdoor in your code Quality Assurance: I'm guessing that's why you hired them in the first place because you know they deliver quality service.
upvoted 6 times
...
Protract8593
Most Recent 1 year, 9 months ago
Selected Answer: C
The GREATEST security concern when outsourcing code development to third-party contractors for an internet-facing application is the possibility of an unknown backdoor being introduced into the code. An unknown backdoor refers to unauthorized access points deliberately inserted into the software without the knowledge or consent of the organization. When outsourcing code development, the organization has less direct control over the development process and may not have full visibility into the contractor's practices. This lack of oversight could potentially lead to the inclusion of hidden backdoors, which can be exploited by malicious actors to gain unauthorized access to the application and its data.
upvoted 3 times
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: C
While intellectual property theft, elevated privileges, and quality assurance are all important considerations when outsourcing code development, the presence of an unknown backdoor poses the greatest security risk. An unknown backdoor is a hidden entry point or vulnerability intentionally or unintentionally inserted into the code by a malicious or compromised developer. It can provide unauthorized access to the application or its underlying systems, allowing attackers to exploit the application's functionality or compromise sensitive data. An unknown backdoor can be difficult to detect and may remain undetected for an extended period, allowing attackers to maintain persistent access and potentially exploit the application or compromise the organization's systems or data. It can bypass security controls and enable unauthorized actions, posing a significant risk to the security and integrity of the internet-facing application.
upvoted 3 times
...
ronniehaang
2 years, 3 months ago
Selected Answer: C
The greatest security concern when outsourcing code development to third-party contractors for an internet-facing application is the possibility of an unknown backdoor. This is because a contractor may intentionally or unintentionally insert malicious code into the application that could compromise the security and privacy of user data and the organization's systems. This risk is elevated if the contractor is not fully vetted, or if the organization does not have adequate safeguards in place to ensure the security and integrity of the codebase. To mitigate this risk, the organization should have strict security policies and procedures in place for outsourcing, including background checks for contractors, code review and testing procedures, and continuous monitoring and incident response processes.
upvoted 2 times
...
DALLASCOWBOYS
2 years, 3 months ago
C. I think Unknown Backdoors would be the GREATEST security concern is the best answer. I do believe D is very good answer because that would be the first step in risk assessment and mitigation is Quality Assurance.
upvoted 1 times
...
sonic1230
2 years, 6 months ago
Selected Answer: C
google
upvoted 3 times
...
comeragh
2 years, 8 months ago
Selected Answer: C
GREATEST security concern - for me this would be C - Unknown Backdoor
upvoted 1 times
...
stoneface
2 years, 8 months ago
Selected Answer: D
If you're outsourcing dev work, you probably have a contract with a legit company and you had probably also reviewed their documents and AOC's and stuff. Without good QA, there could be a purposeful OR unintended backdoor in the application if somebody was an incompetent developer With good QA, ideally they would be doing automated security testing to look for a backdoor in the program.
upvoted 2 times
Sandon
2 years, 3 months ago
Bad Stoneface, bad
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago