🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

During a pre-release audit, you learn that developers statically linked an image-processing library released under the GNU GPLv3 into a proprietary application the company intends to sell. Management wants to keep the application closed source but still needs the same functionality. Which corrective control best mitigates the risk of violating the open-source license?

  • Distribute only compiled binaries of the application and store the proprietary source code in encrypted escrow.

  • Keep the GPL component and add an attribution notice in product documentation before commercial distribution.

  • Release the whole application's source code under GPLv3 to comply fully with the library's copyleft requirements.

  • Replace the GPL library with an equivalent component distributed under a permissive license (for example, MIT or BSD) after confirming technical compatibility.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot