ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While finalizing a contract for a proprietary analytics engine, the security architect worries that the small vendor could be acquired or go out of business, leaving the organization unable to patch future security vulnerabilities. Which contractual mechanism best ensures the organization can obtain the source code under such trigger events and legally continue maintenance?
Insert a limitation-of-liability clause capping the vendor's damages at the value of the license fees paid.
Negotiate a service-level agreement that mandates patch delivery within a defined time frame.
Add a twelve-month warranty clause requiring the vendor to correct any defects discovered during that period.
Include a source code escrow agreement that releases the code if the vendor fails to meet support obligations.
A code escrow agreement places the vendor's source code with a neutral third party and defines specific "release conditions," such as bankruptcy, acquisition, or failure to provide agreed-upon support. When a release condition occurs, the escrow agent hands the source code to the customer, who may then maintain or modify the software without violating the original license. A warranty clause only promises a level of product quality, an SLA defines response times, and a limitation-of-liability clause merely caps financial exposure-none of these guarantee access to the source code itself.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a source code escrow agreement?
Open an interactive chat with Bash
Why doesn't a warranty clause address vendor-related risks like bankruptcy?
Open an interactive chat with Bash
How is a service-level agreement (SLA) different from a source code escrow agreement?
Open an interactive chat with Bash
What is a source code escrow agreement?
Open an interactive chat with Bash
Why is a warranty clause not sufficient for securing future software patches?
Open an interactive chat with Bash
How does a service-level agreement differ from a source code escrow agreement?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .