Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)

⚠ Common exam trap

CAS-005 often tests which security activities belong 'early' in the SDLC, so candidates who include penetration testing (late-stage) or SBOM analysis (dependency inventory, not code testing) instead of the design/code/runtime trio of threat modeling, SAST, and DAST lose marks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat modeling

Threat modeling (C) is correct because it is a design-phase activity that systematically identifies threats, attack surfaces, and mitigations before code is written, making it a foundational shift-left technique. SAST (E) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find flaws such as injection sinks and insecure coding patterns directly in the IDE or CI pipeline. DAST (D) is correct because it tests the running application from the outside, exercising inputs and runtime behavior to uncover vulnerabilities like authentication and configuration flaws that static analysis may miss. Penetration testing (A) is not one of the three because it is typically a later, point-in-time adversarial assessment rather than an early development-phase code-testing technique, and SBOM analysis (B) is a supply-chain inventory and component-transparency practice, not a method for finding vulnerabilities in first-party code during development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Penetration testing

    Why it's wrong here

    Penetration testing exercises a running system from an attacker's viewpoint, so it cannot inspect source code during development. It is tempting because it genuinely validates exploitable weaknesses in deployed environments, and would be the right choice when assessing a live application's defences rather than finding coding flaws early.

  • ✗

    Software Bill of Materials (SBOM) analysis

    Why it's wrong here

    SBOM analysis inventories components and dependencies, so it flags vulnerable or unapproved third-party libraries rather than finding flaws in code the team writes. It is tempting because supply-chain visibility genuinely matters, and SBOM generation would be the right choice when the requirement is tracking transitive dependencies or responding to a newly disclosed library vulnerability.

  • ✓

    Threat modeling

    Why this is correct

    Threat modelling identifies design-level weaknesses by systematically analysing data flows, trust boundaries and attack paths before coding completes. Applying it early satisfies the stem's requirement to find vulnerabilities during development, complementing code-level scanning with architectural risk discovery.

  • ✓

    Dynamic Application Security Testing (DAST)

    Why this is correct

    DAST tests the running application from the outside, exercising inputs and observing responses to expose runtime flaws such as injection and authentication bypass. It complements code-level techniques within the SDLC, though it requires a deployed build, so it is applied later than static analysis rather than at the earliest development stages.

  • ✓

    Static Application Security Testing (SAST)

    Why this is correct

    SAST examines source code without executing it, tracing data flows to flag injection, unsafe APIs and hardcoded secrets before compilation. This satisfies the SDLC goal of shifting security testing early, since developers receive findings while code is still being written rather than after deployment.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.