mediumMultiple Select
CAS-004 Practice Question: Adopting a secure software development lifecycle…
A company is adopting a secure software development lifecycle (SDLC). Which two practices are most effective for identifying vulnerabilities early in the development process? (Select TWO.)
⚠ Common exam trap
CompTIA often tests the distinction between early-phase (SAST, code reviews) and late-phase (DAST, RASP, pentesting) security practices, and the trap here is that candidates may confuse DAST or RASP as 'early' because they are automated, when in fact they require a running application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regular code reviews with security focus
Option C (regular code reviews with security focus) is correct because peer review of source code during development catches insecure patterns, logic flaws, and missing input validation before code is merged, making it an early-phase practice in a secure SDLC. Option D (SAST integrated into the IDE) is correct because static analysis examines source code without executing it and, when embedded in the developer's IDE, flags vulnerabilities such as injection flaws or hardcoded secrets at the moment of coding, which is the earliest practical detection point. Option A (RASP) is not correct here because RASP instruments a running application to detect and block attacks at runtime, which is a production protection mechanism rather than an early development-phase identification practice. Option B (DAST) is not correct because it tests a deployed, running application from the outside, so it occurs later in the lifecycle and cannot inspect source code early. Option E (penetration testing after deployment) is not correct because it is a post-deployment, point-in-time assessment that identifies vulnerabilities only after the code is already in production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Runtime application self-protection (RASP)
Why it's wrong here
RASP instruments a running application to block attacks at execution time, so it detects nothing during design or coding. It tempts because it addresses vulnerabilities, but its lifecycle position is production runtime, the opposite end from early identification.
- ✗
Dynamic application security testing (DAST)
Why it's wrong here
DAST exercises a deployed, running application from outside, so it cannot run before code exists or is built. It tempts because it genuinely finds vulnerabilities, but its lifecycle position is testing of assembled artefacts, later than code-level review.
- ✓
Regular code reviews with security focus
Why this is correct
Security-focused code reviews catch flaws at the source, before code merges or reaches testing. Reviewers inspect authentication logic, input validation and cryptographic usage against the team's secure coding standards, satisfying the stem's requirement to identify vulnerabilities early in development rather than after deployment. This shifts remediation to the cheapest possible point in the lifecycle.
- ✓
Static application security testing (SAST) integrated into the IDE
Why this is correct
SAST in the IDE flags insecure code as developers write it, giving immediate feedback at the earliest SDLC stage. This satisfies the requirement to identify vulnerabilities early, before code reaches the shared repository or build pipeline.
- ✗
Penetration testing after deployment
Why it's wrong here
Penetration testing occurs after deployment, by definition too late to identify vulnerabilities early in development. It tempts because it is a legitimate vulnerability-discovery method, but its lifecycle position is post-release assurance, not design or coding.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.