Professional Ethics & Standards Flashcards
7 cards from real AAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Professional Ethics & Standards flashcards as text
You discover a critical security vulnerability in a popular third-party Android library your app depends on. What is the ethical course of action?
Answer: Privately disclose the vulnerability to the maintainer and allow reasonable time to patch before any public disclosure
Responsible disclosure gives maintainers time to patch the issue before attackers can exploit public knowledge of the vulnerability.
Your Android app bundles an open-source library licensed under GPL v2. What legal and ethical obligation does this create?
Answer: You may be required to release your app's source code under a GPL-compatible license
The GPL is a copyleft license that typically requires derivative works to also be distributed under the GPL.
Which open-source license allows you to include a library in a closed-source commercial Android app without sharing your source code?
Answer: MIT License
The MIT License is a permissive license that imposes no requirement to open-source your own code, making it compatible with proprietary apps.
A security researcher contacts you to report a vulnerability in your published Android app. What is the industry-standard ethical response?
Answer: Acknowledge the report, fix the issue promptly, and credit the researcher with their consent
A professional bug bounty culture encourages researchers to report responsibly, which improves security for all users.
When storing sensitive authentication tokens in an Android app, which approach is most secure and ethical?
Answer: Use the Android Keystore System to protect cryptographic keys
The Android Keystore System stores keys in secure hardware, preventing extraction even if the device is compromised.
What does 'responsible disclosure' mean in the context of a discovered Android platform vulnerability?
Answer: Privately notifying the vendor and allowing a standard window (e.g., 90 days) to patch before going public
Responsible disclosure balances the public's right to know with the vendor's need for time to develop and deploy a fix.
Which action constitutes a violation of open-source licensing ethics when distributing an Android app?
Answer: Stripping copyright notices from Apache 2.0-licensed source code before bundling it
Apache 2.0 requires preservation of copyright notices and attribution; removing them is both unethical and a license violation.