CISA Practice Question: Information Systems Acquisition, Development, and Implementation
Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?
⚠ Common exam trap
CISA often tests the confusion between SAST (static, code-level, security) and DAST (dynamic, runtime, security) or functional testing, causing candidates to pick a non-security or runtime option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To identify security vulnerabilities in the source code
Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, to identify security vulnerabilities such as SQL injection, buffer overflows, and insecure cryptographic practices. Its primary purpose during development is to find security flaws early in the SDLC, when they are cheaper to fix. It does not validate business requirements or runtime behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To ensure the application is free of runtime errors
Why it's wrong here
SAST analyses source code, bytecode or binaries for coding flaws such as injection and buffer overflows; it does not execute the program, so runtime errors cannot be detected. Runtime error detection belongs to dynamic testing, which is why SAST is tempting here despite examining code rather than executing it.
- ✗
To validate that the application meets business requirements
Why it's wrong here
SAST inspects code for security weaknesses, not functional conformance to business requirements, which is established through requirements traceability and functional testing. It is tempting because both occur during development, yet SAST targets exploitable coding defects rather than whether the delivered features match what the business asked for.
- ✓
To identify security vulnerabilities in the source code
Why this is correct
SAST analyses source code without executing it, tracing data flows to flag injection, buffer and input-validation flaws during development. This satisfies the stem's development-phase purpose: identifying security vulnerabilities in the source code before deployment, when fixes are cheapest.
- ✗
To test the application's performance under load
Why it's wrong here
Load and performance testing require executing the application under concurrent user or transaction volumes, which static analysis never does because it examines code without running it. SAST finds insecure coding patterns instead; performance measurement is the domain of dynamic performance testing tools.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.