ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your DevOps team is preparing to deploy a new customer-facing SaaS application on a public cloud. A container image pulled from a public registry includes a cryptographic library released under the GNU Affero General Public License (AGPL). Management insists that all proprietary application code must remain closed source after deployment. Which action is the most appropriate way to address this third-party licensing risk without delaying the release?

  • Replace the AGPL-licensed library with a functionally equivalent component released under a permissive license such as MIT or Apache 2.0.

  • Negotiate a private fork of the AGPL library under a nondisclosure agreement and proceed without any further changes.

  • Keep the AGPL component and meet the license terms by releasing the entire SaaS application's source code to all users.

  • Continue using the AGPL library because its obligations apply only when software binaries are distributed, not when accessed as a service.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot