ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During an operational risk analysis, you discover that developers intend to statically link a GPLv3-licensed image-processing library into the company's proprietary desktop application, which will be shipped to customers. Which copyright-related risk should be highlighted to management?

  • The company must purchase a separate commercial license from the library's authors before any internal or external use.

  • The product must display an open-source attribution notice, but the proprietary code can remain closed-source without further obligations.

  • GPLv3's copyleft terms could compel the company to release the entire application's source code under the same license, eliminating its proprietary protection.

  • All company-held patents would be automatically transferred to the maintainers of the GPL project upon distribution of the product.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot