CAS-004 Security Architecture Practice Question
During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?
⚠ Common exam trap
CAS-005 often tests the confusion between SAST (static, pre-compilation, white-box) and DAST/IAST/RASP (dynamic, runtime, black-box or instrumented), tricking candidates who focus on 'testing' rather than on when the code is analyzed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SAST
SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, making it the correct choice for finding vulnerabilities before compilation. It integrates into the IDE or CI pipeline and can flag issues like hardcoded secrets, injection flaws, and insecure API usage at the code level. Because it works on the code itself, it is the only option that fits the 'before it is compiled' requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DAST
Why it's wrong here
DAST probes a deployed, running application from the outside, sending requests and analysing responses, so it needs compiled, executing code. It fits testing live environments for runtime and configuration flaws, not inspecting source before compilation.
- ✓
SAST
Why this is correct
SAST analyses source code statically, before compilation or execution, tracing tainted data flows to flag injection flaws, unsafe functions and hardcoded secrets. That directly matches the requirement to identify vulnerabilities in source code early, whereas DAST and IAST need a running or instrumented build.
- ✗
IAST
Why it's wrong here
IAST instruments a running application, typically via an agent during execution, so it requires compiled, deployed code and exercised endpoints. It suits testing within a running test environment; scanning unbuilt source for flaws is static analysis performed directly on the code.
- ✗
RASP
Why it's wrong here
RASP runs inside an application at runtime, detecting and blocking attacks as they execute, so it requires compiled deployed code. It suits production protection against live exploitation, not pre-compilation review of source code for vulnerabilities.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.