ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is selecting an open-source encryption library to embed in a closed-source SaaS offering that will be distributed to customers. Which license feature would most endanger your ability to keep the company's proprietary code confidential once the service is delivered?
The library carries the MIT License, obligating only preservation of the original copyright notice.
The library is licensed under GNU GPLv3, requiring any derivative software to be released under the same license.
The library uses the Apache License 2.0, which includes a patent grant to recipients.
The library is under the GNU LGPL, permitting dynamic linking without disclosure of proprietary source code.
The GNU General Public License v3 is a strong copyleft license. If a GPL-licensed component is incorporated into a larger program and that program is distributed to customers, the entire derivative work must be released under the GPL. This obligation would force the organization to provide its proprietary source code, conflicting with the goal of keeping it confidential.
By contrast, the MIT License is permissive, generally requiring only that copyright and license notices be retained, so it does not compel source-code disclosure. The Apache License 2.0 does include a patent grant and notice requirements, but it also allows proprietary derivatives. The GNU Lesser GPL (LGPL) is less restrictive than GPL; it allows dynamic linking without obligating the release of the entire application's source code, provided modifications to the library itself are shared. Therefore, the GPLv3 reciprocal requirement presents the greatest legal risk to proprietary code.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'copyleft' mean in licensing?
Open an interactive chat with Bash
What is the main difference between GPL and LGPL?
Open an interactive chat with Bash
Why is the Apache License 2.0 considered permissive?
Open an interactive chat with Bash
What does 'strong copyleft' mean in the context of software licenses?
Open an interactive chat with Bash
How does the GNU Lesser General Public License (LGPL) differ from the GNU General Public License (GPL)?
Open an interactive chat with Bash
Why is the MIT License considered a permissive license?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .