Attackers breach the remote-support platform used by the city’s managed service provider and then reach multiple municipal endpoints through that trusted tooling. Which attack surface best describes this event?
Select an answer to reveal the explanation.
Short Explanation
When the MSP’s remote-support tools get owned, the city inherits a supply-chain problem — trust in the vendor channel becomes the attacker’s highway. That is different from SQLi in a permit app or a buffer overflow on a scanner box. Treat MSP access like privileged infrastructure and monitor it accordingly.
Full Explanation
Supply-chain attack surfaces include compromised vendors, suppliers, and managed service providers whose trusted remote access can pivot into customer environments. Objective 2.2 explicitly includes MSP/vendor/supplier pathways. SQL injection, mobile jailbreaking, and buffer overflows are vulnerability types rather than this vendor-channel vector. Municipal contracts and monitoring should assume MSP tooling can become an entry point.