Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?

⚠ Common exam trap

CAS-005 often tests the confusion between SAST (static, pre-compilation, white-box) and DAST/IAST/RASP (dynamic, runtime, black-box or instrumented), tricking candidates who focus on 'testing' rather than on when the code is analyzed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAST

SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, making it the correct choice for finding vulnerabilities before compilation. It integrates into the IDE or CI pipeline and can flag issues like hardcoded secrets, injection flaws, and insecure API usage at the code level. Because it works on the code itself, it is the only option that fits the 'before it is compiled' requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DAST

    Why it's wrong here

    DAST probes a deployed, running application from the outside, sending requests and analysing responses, so it needs compiled, executing code. It fits testing live environments for runtime and configuration flaws, not inspecting source before compilation.

  • ✓

    SAST

    Why this is correct

    SAST analyses source code statically, before compilation or execution, tracing tainted data flows to flag injection flaws, unsafe functions and hardcoded secrets. That directly matches the requirement to identify vulnerabilities in source code early, whereas DAST and IAST need a running or instrumented build.

  • ✗

    IAST

    Why it's wrong here

    IAST instruments a running application, typically via an agent during execution, so it requires compiled, deployed code and exercised endpoints. It suits testing within a running test environment; scanning unbuilt source for flaws is static analysis performed directly on the code.

  • ✗

    RASP

    Why it's wrong here

    RASP runs inside an application at runtime, detecting and blocking attacks as they execute, so it requires compiled deployed code. It suits production protection against live exploitation, not pre-compilation review of source code for vulnerabilities.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.