Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?

⚠ Common exam trap

A common mix-up: candidates confuse different types of security testing and their appropriate stages in the SDLC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static application security testing (SAST) integrated into the build process.

Integrating SAST into the build process enables automated security testing on every code commit, providing immediate feedback to developers. This shifts security left, allowing vulnerabilities to be found and fixed early when they are cheaper and easier to remediate. SAST is well-suited for CI/CD pipelines because it does not require a running application and can be triggered automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Static application security testing (SAST) integrated into the build process.

    Why this is correct

    SAST analyzes source code or binaries for vulnerabilities without executing the application. Integrating it into the build process allows developers to receive immediate feedback on security issues as they commit code. This shifts security left, enabling early remediation and reducing the cost of fixes. SAST is ideal for identifying issues like SQL injection and cross-site scripting early in the SDLC.

  • ✗

    Interactive application security testing (IAST) run manually by the security team quarterly.

    Why it's wrong here

    IAST combines static and dynamic techniques and can be effective, but running it manually quarterly does not provide immediate feedback. It also may not be integrated into the CI/CD pipeline, delaying vulnerability detection. For early and continuous feedback, IAST should be automated and integrated into the pipeline, but the scenario specifies manual quarterly runs, which is insufficient.

  • ✗

    Software composition analysis (SCA) performed only before major releases.

    Why it's wrong here

    SCA identifies vulnerabilities in third-party dependencies, which is important, but performing it only before major releases is infrequent and does not provide immediate feedback to developers. It also does not cover custom code vulnerabilities. To shift left, SCA should be automated in the CI/CD pipeline and run on every build, not just before releases.

  • ✗

    Dynamic application security testing (DAST) run after deployment to production.

    Why it's wrong here

    DAST is typically run against running applications, often in staging or production, and identifies vulnerabilities from an external perspective. However, running it only after deployment to production is too late; vulnerabilities should be caught earlier. It also does not provide immediate feedback to developers during coding. DAST is better suited for later stages, not early in the SDLC.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.