CAS-004 Security Architecture Practice Question
During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?
⚠ Common exam trap
CAS-005 often tests the mapping of security activities to SDLC phases — candidates confuse SAST (code/implementation) and DAST (testing/runtime) with design-phase activities, forgetting that threat modeling is the only one that works before code exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat modeling
Threat modeling is a structured design-phase activity that identifies potential threats, attack vectors, and design weaknesses before code is written. It uses frameworks like STRIDE or PASTA to map data flows and trust boundaries, surfacing architectural flaws early when they're cheapest to fix. This aligns exactly with the goal of identifying design flaws during the design phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat modeling
Why this is correct
Threat modelling examines data flows, trust boundaries and architecture during design, exposing flaws before code exists, when remediation is cheapest. It directly satisfies the requirement to identify design flaws early, unlike code scanning or penetration testing, which occur later.
- ✗
Penetration testing
Why it's wrong here
Penetration testing exercises a running system, so it cannot examine design artefacts and occurs after code exists. It is tempting because it finds exploitable weaknesses, but those are implementation and configuration flaws. Penetration testing belongs in verification or operations, once a deployable build exists.
- ✗
Dynamic application security testing (DAST)
Why it's wrong here
DAST probes a deployed, running application from outside, so no executable exists during design to test. It is tempting because it detects runtime and configuration weaknesses, but it cannot inspect architecture or data-flow models. DAST belongs in testing or operations, after the application is built and reachable.
- ✗
Static application security testing (SAST)
Why it's wrong here
SAST scans source code for coding defects, so it requires implementation artefacts that do not exist during design. It is tempting because it finds flaws early and cheaply, but those are code-level issues, not design flaws. SAST belongs in the coding phase, once source is written.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.