Courseiva
Asset Security →mediumMultiple Choice

CISSP Asset Security Practice Question

A company's software asset management team discovers an unauthorized copy of a licensed application installed on several employee workstations. What is the primary risk associated with this finding?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legal liability for software piracy

Unauthorized software can expose the organization to legal liability for copyright infringement, security vulnerabilities due to lack of patching, and compliance issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Legal liability for software piracy

    Why this is correct

    Unauthorized software directly constitutes a breach of intellectual property rights and software licensing agreements. This exposes the company to significant legal action from software vendors, potentially resulting in substantial fines, penalties, and mandatory compliance audits. Such legal repercussions can severely impact the organization's financial stability and reputation, making it the most immediate and severe risk identified by a software asset management team.

  • ✗

    Reduction in employee productivity

    Why it's wrong here

    While unauthorized software might lack proper support or introduce system instability, potentially leading to downtime or workarounds that reduce employee productivity, this operational impact is generally secondary. The immediate and direct risk from a software asset management discovery is not primarily about productivity loss but rather the severe legal and security implications of non-compliance. Productivity issues are a downstream effect, not the core problem identified by SAM.

  • ✗

    Increased storage consumption

    Why it's wrong here

    Unauthorized software, like any installed application, will consume disk space on company systems. However, the incremental storage consumption from a few instances of unauthorized software is typically a minor operational concern. It does not represent the primary or most critical risk to the organization compared to the severe legal, financial, or security vulnerabilities associated with unapproved installations.

  • ✗

    Incompatibility with other systems

    Why it's wrong here

    Unauthorised licensed software creates legal and financial exposure through licence non-compliance, plus unpatched, unsupported code risks. Incompatibility is a technical deployment concern, not the primary risk of unlicensed installation. Incompatibility is tempting because rogue installs can destabilise workstations, and it would be correct if the finding were a version conflict with supported software.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.