CSL CSL Intellectual Property & Cybersecurity 2 โ Questions and Answers
Question 1: Under U.S. patent law, can cybersecurity methods and software algorithms be patented?
- No, software is categorically excluded from patent protection
- Yes, if they meet the Alice/Mayo test for patent-eligible subject matter (Correct answer)
- Yes, without restriction under 35 U.S.C. ยง 101
- Only if implemented in hardware
Correct answer: Yes, if they meet the Alice/Mayo test for patent-eligible subject matter
After Alice Corp. v. CLS Bank (2014), software patents must demonstrate an inventive concept beyond abstract ideas, requiring application to a specific technological problem.
Question 2: What legal obligation do companies have when they discover a cyberattack that may have compromised third-party copyrighted material stored on their systems?
- No obligation unless they created the infringing copies
- DMCA notice-and-takedown obligations apply
- Immediate disclosure to copyright holders under the DMCA
- Potential contributory infringement liability if they fail to act (Correct answer)
Correct answer: Potential contributory infringement liability if they fail to act
Companies that know of infringing activity on their systems and fail to act may face contributory copyright infringement liability.
Question 3: Which international treaty requires member nations to provide legal protections for technological protection measures similar to the DMCA?
- Berne Convention
- WIPO Copyright Treaty (WCT) (Correct answer)
- TRIPS Agreement
- Budapest Convention
Correct answer: WIPO Copyright Treaty (WCT)
The WIPO Copyright Treaty of 1996 requires signatories to provide adequate legal protection against circumvention of technological protection measures.
Question 4: A penetration tester discovers a critical vulnerability in software and reverse engineers the code to understand it. Under the DMCA, this activity is most protected by:
- Section 1201(f) interoperability exception
- Section 1201(g) encryption research exception
- Section 1201(j) security research exception (Correct answer)
- Fair use under Section 107
Correct answer: Section 1201(j) security research exception
Section 1201(j) specifically covers security testing when the researcher owns the system or has authorization, making it the most applicable DMCA exception.
Question 5: What is the primary legal risk of releasing a cybersecurity tool (e.g., exploit code) that has both offensive and defensive uses?
- Copyright infringement of the vulnerability it targets
- Liability under DMCA Section 1201 for circumvention tools
- Export control violations under the EAR
- All of the above (Correct answer)
Correct answer: All of the above
Dual-use cybersecurity tools may implicate DMCA anti-circumvention provisions, export controls under the EAR for intrusion software, and potential CFAA liability.
Question 6: Under the Economic Espionage Act (EEA), what makes trade secret theft a federal crime distinct from civil trade secret misappropriation?
- The value of the trade secret must exceed $5 million
- The theft must benefit a foreign government or instrumentality (Correct answer)
- The theft must involve computer access
- Prosecution requires DOJ authorization
Correct answer: The theft must benefit a foreign government or instrumentality
The EEA specifically criminalizes trade secret theft that benefits a foreign government, instrumentality, or agent, distinguishing it from general commercial theft under 18 U.S.C. ยง 1832.
Under U.S. patent law, can cybersecurity methods and software algorithms be patented?