โ† All CSA Flashcard Decks

Regulatory Compliance & Licensing Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Licensing flashcards as text
  1. Under Sarbanes-Oxley (SOX) Section 404, which party is responsible for assessing and reporting on the effectiveness of internal controls over financial reporting?

    Answer: Company management, with external auditor attestation

    SOX Section 404 requires management to assess and report on ICFR effectiveness, and the external auditor must attest to and report on that assessment.

  2. A perpetual software license differs from a subscription license primarily in that a perpetual license:

    Answer: Grants the right to use a specific software version indefinitely after a one-time purchase

    A perpetual license grants indefinite rights to use a specific version of the software for a single upfront payment, though ongoing maintenance may require separate fees.

  3. When performing a software asset management (SAM) audit, an administrator discovers 50 installations of software for which only 30 licenses exist. This condition is best described as:

    Answer: License overdeployment

    License overdeployment (also called underlicensing) occurs when the number of software installations exceeds the number of valid licenses owned.

  4. The GNU General Public License (GPL) v3 requires that when distributing modified GPL-licensed software in binary form, you must also:

    Answer: Provide access to the corresponding source code

    GPL v3 requires that distributors of modified binaries provide corresponding complete source code under the same GPL v3 license terms.

  5. FISMA requires federal agencies to categorize their information systems using which framework to determine appropriate security controls?

    Answer: NIST FIPS 199 and SP 800-53

    FISMA mandates use of FIPS 199 for categorizing systems as Low, Moderate, or High impact, then applying corresponding NIST SP 800-53 controls.

  6. A healthcare organization using a cloud EHR system must ensure their cloud provider signs which specific HIPAA document before sharing protected health information?

    Answer: Business Associate Agreement (BAA)

    HIPAA requires covered entities to execute a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits PHI on their behalf.

  7. Which license type is most appropriate for an organization that wants to use open-source software in a proprietary product without being required to release their modifications?

    Answer: MIT License

    The MIT License is a permissive open-source license that allows incorporation into proprietary software without requiring disclosure of modifications.