nerdexam
CompTIA

CAS-002 · Question #776

A company sales manager received a memo from the company's financial department which stated that the company would not be putting its software products through the same security testing as previous…

The correct answer is B. Consult the company's legal department on practices and law. When a company reduces security testing while keeping SLAs and marketing claims unchanged, this creates a potential legal liability that requires internal legal review before sales targets are pursued.

Integration of Computing, Communications and Business Disciplines

Question

A company sales manager received a memo from the company's financial department which stated that the company would not be putting its software products through the same security testing as previous years to reduce the research and development cost by 20 percent for the upcoming year. The memo also stated that the marketing material and service level agreement for each product would remain unchanged. The sales manager has reviewed the sales goals for the upcoming year and identified an increased target across the software products that will be affected by the financial department's change. All software products will continue to go through new development in the coming year. Which of the following should the sales manager do to ensure the company stays out of trouble?

Options

  • ADiscuss the issue with the software product's user groups
  • BConsult the company's legal department on practices and law
  • CContact senior finance management and provide background information
  • DSeek industry outreach for software practices and law

How the community answered

(34 responses)
  • A
    21% (7)
  • B
    65% (22)
  • C
    9% (3)
  • D
    6% (2)

Why each option

When a company reduces security testing while keeping SLAs and marketing claims unchanged, this creates a potential legal liability that requires internal legal review before sales targets are pursued.

ADiscuss the issue with the software product's user groups

Discussing the issue with user groups exposes the security reduction to customers before internal legal and compliance review has occurred, potentially worsening the company's liability.

BConsult the company's legal department on practices and lawCorrect

Consulting the legal department is the correct first step because the unchanged SLAs and marketing materials legally commit the company to security standards that will no longer be validated after testing cuts. This discrepancy could constitute misrepresentation or breach of contract, creating significant legal exposure for the company. The legal team can advise whether the SLA must be amended or disclosures made before the increased sales push proceeds.

CContact senior finance management and provide background information

Senior finance management originated the decision and lacks the authority and expertise to resolve the legal conflict between reduced security practices and existing contractual SLA commitments.

DSeek industry outreach for software practices and law

Industry outreach is an external, non-authoritative channel that cannot resolve the company's specific contractual and legal obligations tied to its own SLAs.

Concept tested: Legal and compliance obligations tied to SLA commitments

Topics

#legal compliance#SLA obligations#software security testing#contractual risk

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice