ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During procurement you review a vendor's SDK EULA. It grants your company a perpetual, royalty-free license to use the SDK "for internal business purposes only." Your team plans to embed the SDK in a commercial mobile app that will be sold to customers. What is the main compliance risk posed by this clause?
It obliges you to release any derivative work under an open-source copyleft license, exposing your proprietary code.
It imposes export-control restrictions that categorically block sales to all non-U.S. markets.
It transfers ownership of any application that uses the SDK to the vendor, jeopardizing your intellectual property.
The clause prohibits redistribution, so including the SDK in a product sold to customers would violate the license.
An "internal business purposes only" clause limits the licensee to using the software within its own organization; it does not grant the right to redistribute the software to third parties. Embedding the SDK in a product that will be sold externally would exceed the scope of the license and constitute a contract breach. The clause says nothing about open-sourcing code, transferring IP ownership, or general export bans, and patch-support terms, while potentially concerning, do not in themselves forbid resale. Therefore, the key risk is that redistribution in a commercial app would violate the EULA.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SDK EULA?
Open an interactive chat with Bash
What does 'internal business purposes only' mean in a licensing agreement?
Open an interactive chat with Bash
What is the compliance risk of redistributing software against EULA terms?
Open an interactive chat with Bash
What is an SDK EULA?
Open an interactive chat with Bash
What does 'internal business purposes only' mean in a license agreement?
Open an interactive chat with Bash
What are the consequences of violating an SDK EULA?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .