ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During procurement you review a vendor's SDK EULA. It grants your company a perpetual, royalty-free license to use the SDK "for internal business purposes only." Your team plans to embed the SDK in a commercial mobile app that will be sold to customers. What is the main compliance risk posed by this clause?

  • The clause prohibits redistribution, so including the SDK in a product sold to customers would violate the license.

  • It obliges you to release any derivative work under an open-source copyleft license, exposing your proprietary code.

  • It imposes export-control restrictions that categorically block sales to all non-U.S. markets.

  • It transfers ownership of any application that uses the SDK to the vendor, jeopardizing your intellectual property.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot