Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?

⚠ Common exam trap

CAS-005 often tests the mapping of security activities to SDLC phases — candidates confuse SAST (code/implementation) and DAST (testing/runtime) with design-phase activities, forgetting that threat modeling is the only one that works before code exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat modeling

Threat modeling is a structured design-phase activity that identifies potential threats, attack vectors, and design weaknesses before code is written. It uses frameworks like STRIDE or PASTA to map data flows and trust boundaries, surfacing architectural flaws early when they're cheapest to fix. This aligns exactly with the goal of identifying design flaws during the design phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat modeling

    Why this is correct

    Threat modelling examines data flows, trust boundaries and architecture during design, exposing flaws before code exists, when remediation is cheapest. It directly satisfies the requirement to identify design flaws early, unlike code scanning or penetration testing, which occur later.

  • ✗

    Penetration testing

    Why it's wrong here

    Penetration testing exercises a running system, so it cannot examine design artefacts and occurs after code exists. It is tempting because it finds exploitable weaknesses, but those are implementation and configuration flaws. Penetration testing belongs in verification or operations, once a deployable build exists.

  • ✗

    Dynamic application security testing (DAST)

    Why it's wrong here

    DAST probes a deployed, running application from outside, so no executable exists during design to test. It is tempting because it detects runtime and configuration weaknesses, but it cannot inspect architecture or data-flow models. DAST belongs in testing or operations, after the application is built and reachable.

  • ✗

    Static application security testing (SAST)

    Why it's wrong here

    SAST scans source code for coding defects, so it requires implementation artefacts that do not exist during design. It is tempting because it finds flaws early and cheaply, but those are code-level issues, not design flaws. SAST belongs in the coding phase, once source is written.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.