Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A software development team is adopting a…

A software development team is adopting a DevSecOps approach. Which of the following practices best integrates security into the continuous integration pipeline?

⚠ Common exam trap

In CompTIA CASP+, a common trap is confusing security activities that are integrated into the CI/CD pipeline (like SAST) with those performed outside the pipeline (like annual training or post-release pen testing). Candidates may also mistake runtime vulnerability scanning for static analysis or think any security activity qualifies as DevSecOps integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Running static application security testing (SAST) on every code commit

Running static application security testing (SAST) on every code commit integrates security directly into the continuous integration (CI) pipeline by automatically analyzing source code for vulnerabilities (e.g., SQL injection, buffer overflows) before the build is compiled. This shift-left approach ensures that security checks are performed as early as possible, aligning with DevSecOps principles of continuous security validation without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Running static application security testing (SAST) on every code commit

    Why this is correct

    Running SAST on every commit embeds automated security checks directly into the CI pipeline, satisfying the DevSecOps requirement for continuous, shift-left testing. Unlike periodic manual reviews or pre-deployment gates, this scans source code at the earliest stage, catching vulnerabilities before they merge and giving developers immediate feedback.

  • ✗

    Conducting annual security training for developers

    Why it's wrong here

    Annual security training operates outside the pipeline entirely, so it cannot inspect commits, dependencies, or build artefacts as code moves through continuous integration. It is tempting because recurring awareness training genuinely satisfies compliance and certification requirements, and it would be the right answer if the stem asked how to build a security-aware culture rather than integrate controls into the CI pipeline itself.

  • ✗

    Using a vulnerability scanner on production servers

    Why it's wrong here

    Scanning production servers detects vulnerabilities after deployment, outside the CI pipeline where code is built and tested. The stem requires security integrated into continuous integration, so findings arrive too late to block a build. Such scanning is correct for runtime or production monitoring, which is why it tempts.

  • ✗

    Performing penetration testing after each release

    Why it's wrong here

    Penetration testing runs after deployment, so it cannot gate commits or block vulnerable builds inside the CI pipeline itself. It is tempting because penetration testing genuinely validates production security posture, and would be the right choice when assessing a deployed system's resilience or meeting periodic assurance requirements.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.