SAM License Compliance & Audits 3 — Questions and Answers
Question 1: Which of the following is considered a 'soft' audit trigger that may prompt a vendor to initiate a license review?
- A customer submitting a formal audit waiver request
- A customer's contract approaching renewal with no upsell activity (Correct answer)
- A customer deploying only open-source alternatives
- A customer maintaining a fully documented SAM program
Correct answer: A customer's contract approaching renewal with no upsell activity
Contracts approaching renewal with flat or declining spend often trigger vendor audits as a tactic to identify upsell opportunities or compliance gaps.
Question 2: What does 'license harvesting' mean in the context of SAM?
- Purchasing licenses in bulk to achieve volume discount pricing
- Reclaiming licenses from inactive or departed users and redeploying them to active users (Correct answer)
- Removing all unlicensed software from endpoints in advance of an audit
- Archiving old license certificates in a centralized repository
Correct answer: Reclaiming licenses from inactive or departed users and redeploying them to active users
License harvesting recovers unused or underused licenses from inactive accounts and reassigns them, reducing the need to purchase additional licenses.
Question 3: A multinational company runs software on servers in the US, UK, and Germany. Which factor most complicates license compliance across these jurisdictions?
- Differences in server hardware specifications across regions
- Varying license terms and geo-restrictions in country-specific EULAs (Correct answer)
- Different time zones affecting usage reporting intervals
- Regional differences in IT department staffing levels
Correct answer: Varying license terms and geo-restrictions in country-specific EULAs
Many software licenses include geographic restrictions, meaning a license purchased in one country may not legally cover deployments in another.
Question 4: In a SAM audit, what is the significance of 'license position' vs. 'compliance position'?
- License position refers to owned entitlements; compliance position compares entitlements to actual deployments (Correct answer)
- They are interchangeable terms used to describe the same audit metric
- License position tracks costs; compliance position tracks user satisfaction
- Compliance position measures patch levels; license position measures install counts
Correct answer: License position refers to owned entitlements; compliance position compares entitlements to actual deployments
License position is the count of owned entitlements, while compliance position is the net result after comparing entitlements against actual deployments to determine over- or under-licensing.
Question 5: A software vendor's license agreement prohibits 'benchmarking' without written consent. In a SAM context, this clause most likely prevents:
- Using the software to measure employee productivity
- Publishing performance comparison data against competing products without approval (Correct answer)
- Conducting internal software usage audits
- Running automated license discovery scans on endpoints
Correct answer: Publishing performance comparison data against competing products without approval
Anti-benchmarking clauses restrict publishing competitive performance comparisons, not internal usage monitoring or discovery activities.
Question 6: During an audit, a vendor claims entitlement to audit a company's cloud-hosted instances of their software. The SAM manager should first:
- Grant immediate access to all cloud consoles to demonstrate good faith
- Review the contract to confirm whether the audit right extends to cloud or SaaS deployments (Correct answer)
- Migrate all workloads to an alternative platform before the audit begins
- Dispute the audit on the grounds that cloud deployments are outside vendor jurisdiction
Correct answer: Review the contract to confirm whether the audit right extends to cloud or SaaS deployments
Audit rights are contractually defined, and the contract must be reviewed to determine whether the vendor's right to audit extends to cloud-hosted or SaaS environments.
Question 7: Which ISO standard provides guidance specifically for Software Asset Management processes and is widely referenced in SAM audits?
- ISO/IEC 27001
- ISO/IEC 19770-1 (Correct answer)
- ISO/IEC 20000-1
- ISO 9001
Correct answer: ISO/IEC 19770-1
ISO/IEC 19770-1 defines the framework and requirements for SAM processes, and compliance with it is often used as evidence of a mature SAM program during audits.
Which of the following is considered a 'soft' audit trigger that may prompt a vendor to initiate a license review?