CAS-004 Security Architecture Practice Question
A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?
⚠ Common exam trap
A common mix-up: candidates confuse different types of security testing and their appropriate stages in the SDLC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static application security testing (SAST) integrated into the build process.
Integrating SAST into the build process enables automated security testing on every code commit, providing immediate feedback to developers. This shifts security left, allowing vulnerabilities to be found and fixed early when they are cheaper and easier to remediate. SAST is well-suited for CI/CD pipelines because it does not require a running application and can be triggered automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static application security testing (SAST) integrated into the build process.
Why this is correct
SAST analyzes source code or binaries for vulnerabilities without executing the application. Integrating it into the build process allows developers to receive immediate feedback on security issues as they commit code. This shifts security left, enabling early remediation and reducing the cost of fixes. SAST is ideal for identifying issues like SQL injection and cross-site scripting early in the SDLC.
- ✗
Interactive application security testing (IAST) run manually by the security team quarterly.
Why it's wrong here
IAST combines static and dynamic techniques and can be effective, but running it manually quarterly does not provide immediate feedback. It also may not be integrated into the CI/CD pipeline, delaying vulnerability detection. For early and continuous feedback, IAST should be automated and integrated into the pipeline, but the scenario specifies manual quarterly runs, which is insufficient.
- ✗
Software composition analysis (SCA) performed only before major releases.
Why it's wrong here
SCA identifies vulnerabilities in third-party dependencies, which is important, but performing it only before major releases is infrequent and does not provide immediate feedback to developers. It also does not cover custom code vulnerabilities. To shift left, SCA should be automated in the CI/CD pipeline and run on every build, not just before releases.
- ✗
Dynamic application security testing (DAST) run after deployment to production.
Why it's wrong here
DAST is typically run against running applications, often in staging or production, and identifies vulnerabilities from an external perspective. However, running it only after deployment to production is too late; vulnerabilities should be caught earlier. It also does not provide immediate feedback to developers during coding. DAST is better suited for later stages, not early in the SDLC.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.