ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 342 - CAS-004 discussion

Report
Export

A security architect Is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been Implemented to prevent these types of risks?

A.
Code reviews
Answers
A.
Code reviews
B.
Supply chain visibility
Answers
B.
Supply chain visibility
C.
Software audits
Answers
C.
Software audits
D.
Source code escrows
Answers
D.
Source code escrows
Suggested answer: D

Explanation:

A source code escrow is a legal agreement that involves a third party holding the source code of a software application on behalf of the software vendor and the software licensee. The source code escrow ensures that the licensee can access the source code in case the vendor goes out of business, fails to provide maintenance or support, or breaches the contract terms.

A source code escrow would have prevented the risk of having an old application that is not covered for maintenance anymore because the software company is no longer in business, because it would:

Allow the licensee to obtain the source code and continue to update, fix, or modify the application according to their needs.

Protect the vendor’s intellectual property rights and prevent unauthorized disclosure or use of the source code.

Provide a legal framework and a trusted mediator for resolving any disputes or issues between the vendor and the licensee.

asked 02/10/2024
Ramon Lim
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first