ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While defining privacy requirements for a new mobile shopping app that will collect customer email addresses, the project team must ensure compliance with both GDPR and U.S. CAN-SPAM regulations. Which requirement most effectively protects user rights over marketing communications and reduces potential regulatory penalties?
Treat acceptance of the terms of service as consent for marketing; users may opt out by emailing customer support.
Use a pre-ticked checkbox for consent and require users to log in to a separate website to change marketing preferences.
Collect consent through an unchecked box the user must actively select and provide an in-app preferences screen that lets the user withdraw consent at any time, with withdrawals honored within 10 days.
Automatically subscribe every registered user to promotional emails and include an unsubscribe link in each message.
GDPR requires an explicit, affirmative action to grant marketing consent (pre-ticked boxes or implied consent are invalid) and gives data subjects the right to withdraw consent as easily as it was given. CAN-SPAM obliges senders to honor opt-out requests within 10 business days. An unchecked box that users must actively select, coupled with an in-app preference screen that processes withdrawals within the legally mandated period, satisfies both frameworks. Automatically enrolling users, burying consent in terms of service, or relying on pre-ticked boxes either denies true opt-in or makes withdrawal unreasonably difficult, violating these statutes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GDPR and what does it require for marketing consent?
Open an interactive chat with Bash
What obligations does the CAN-SPAM Act place on businesses regarding email marketing?
Open an interactive chat with Bash
What happens if a company uses pre-ticked checkboxes for marketing consent?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .