← All AAD Flashcard Decks

Professional Ethics & Standards Flashcards

7 cards from real AAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Professional Ethics & Standards flashcards as text
  1. You discover a critical security vulnerability in a popular third-party Android library your app depends on. What is the ethical course of action?

    Answer: Privately disclose the vulnerability to the maintainer and allow reasonable time to patch before any public disclosure

    Responsible disclosure gives maintainers time to patch the issue before attackers can exploit public knowledge of the vulnerability.

  2. Your Android app bundles an open-source library licensed under GPL v2. What legal and ethical obligation does this create?

    Answer: You may be required to release your app's source code under a GPL-compatible license

    The GPL is a copyleft license that typically requires derivative works to also be distributed under the GPL.

  3. Which open-source license allows you to include a library in a closed-source commercial Android app without sharing your source code?

    Answer: MIT License

    The MIT License is a permissive license that imposes no requirement to open-source your own code, making it compatible with proprietary apps.

  4. A security researcher contacts you to report a vulnerability in your published Android app. What is the industry-standard ethical response?

    Answer: Acknowledge the report, fix the issue promptly, and credit the researcher with their consent

    A professional bug bounty culture encourages researchers to report responsibly, which improves security for all users.

  5. When storing sensitive authentication tokens in an Android app, which approach is most secure and ethical?

    Answer: Use the Android Keystore System to protect cryptographic keys

    The Android Keystore System stores keys in secure hardware, preventing extraction even if the device is compromised.

  6. What does 'responsible disclosure' mean in the context of a discovered Android platform vulnerability?

    Answer: Privately notifying the vendor and allowing a standard window (e.g., 90 days) to patch before going public

    Responsible disclosure balances the public's right to know with the vendor's need for time to develop and deploy a fix.

  7. Which action constitutes a violation of open-source licensing ethics when distributing an Android app?

    Answer: Stripping copyright notices from Apache 2.0-licensed source code before bundling it

    Apache 2.0 requires preservation of copyright notices and attribution; removing them is both unethical and a license violation.