CAS-005 · Question #436
A security architect is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have…
The correct answer is D. Source code escrows. A source code escrow arrangement ensures that the application’s source code is deposited with a neutral third party and released to the licensee if the vendor goes out of business or fails to meet support obligations. This guarantees continued maintenance and security patches…
Question
A security architect is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been implemented to prevent these types of risks?
Options
- ACode reviews
- BSupply chain visibility
- CSoftware audits
- DSource code escrows
How the community answered
(30 responses)- A10% (3)
- B7% (2)
- C3% (1)
- D80% (24)
Explanation
A source code escrow arrangement ensures that the application’s source code is deposited with a neutral third party and released to the licensee if the vendor goes out of business or fails to meet support obligations. This guarantees continued maintenance and security patches even when the original vendor can no longer provide them, directly preventing the orphan-software risk
Community Discussion
No community discussion yet for this question.