CAP Supply Chain Risk Management 2 — Questions and Answers
Question 1: What is a 'trusted supplier' program in the context of federal ICT procurement?
- A vetting process to identify and use vendors who meet security standards and have demonstrated trustworthiness (Correct answer)
- A program that gives preferred pricing to domestic IT vendors
- A certification program for cloud service providers only
- A list of vendors banned from federal procurement
Correct answer: A vetting process to identify and use vendors who meet security standards and have demonstrated trustworthiness
Trusted supplier programs establish criteria for vetting vendors' security practices, integrity, and supply chain controls before purchasing their products.
Question 2: What supply chain attack vector was demonstrated by the SolarWinds Orion incident?
- Malicious code injected into a legitimate software update distributed to thousands of customers (Correct answer)
- Physical tampering of hardware during shipping
- Exploitation of an unpatched zero-day in the product itself
- Social engineering of SolarWinds customer employees
Correct answer: Malicious code injected into a legitimate software update distributed to thousands of customers
The SolarWinds attack inserted malicious code (SUNBURST) into legitimate software updates that were then distributed and trusted by customers.
Question 3: What is the purpose of a vendor risk assessment in ICT supply chain risk management?
- To evaluate a third-party vendor's security practices, financial stability, and ability to protect government data (Correct answer)
- To negotiate better pricing on hardware procurement
- To verify that a vendor's products are FedRAMP authorized
- To determine which country manufactured the product components
Correct answer: To evaluate a third-party vendor's security practices, financial stability, and ability to protect government data
Vendor risk assessments evaluate whether suppliers have adequate security controls, business continuity plans, and integrity measures to be trusted partners.
Question 4: Which federal law prohibits the use of telecommunications equipment from specific companies deemed national security risks in federal systems?
- National Defense Authorization Act (NDAA) Section 889 (Correct answer)
- Federal Acquisition Regulation (FAR) Part 12
- FISMA Section 3554
- HSPD-12
Correct answer: National Defense Authorization Act (NDAA) Section 889
NDAA Section 889 prohibits federal agencies from procuring or using telecommunications equipment from companies like Huawei and ZTE due to national security concerns.
Question 5: What does 'hardware integrity verification' involve in supply chain risk management?
- Inspecting physical hardware for signs of tampering or counterfeit components before deployment (Correct answer)
- Running antivirus software on newly received computers
- Verifying that hardware serial numbers match purchase orders
- Testing hardware performance against vendor benchmarks
Correct answer: Inspecting physical hardware for signs of tampering or counterfeit components before deployment
Hardware integrity verification checks for physical tampering, counterfeit components, and unauthorized modifications that could introduce security risks.
Question 6: What is the role of acquisition/procurement policies in managing supply chain risks?
- To establish security requirements that vendors must meet before their products or services can be purchased (Correct answer)
- To minimize procurement costs by selecting the lowest bidder
- To ensure all products are purchased from domestic manufacturers
- To automate the ATO process for vendor-hosted systems
Correct answer: To establish security requirements that vendors must meet before their products or services can be purchased
Procurement policies embed security requirements into the buying process so that only vendors meeting security standards can be selected.
What is a 'trusted supplier' program in the context of federal ICT procurement?