CRISC Information Technology and Security Practice Question
A financial services firm is adopting a DevSecOps model. The risk practitioner wants to ensure that security risks are identified and addressed as early as possible in the software development lifecycle. Which of the following practices BEST supports this objective?
⚠ Common exam trap
The trap here is equating any security testing with shifting left; only practices embedded in the early coding and build stages truly identify risks as early as possible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrating static application security testing (SAST) into the continuous integration pipeline.
Integrating SAST into the CI pipeline allows security checks to run automatically with every code commit, giving developers immediate feedback on vulnerabilities. This shifts security left, enabling fixes during development when they are cheapest and fastest to resolve. Other practices like penetration testing, training, and DAST are valuable but do not provide the same early, continuous, code-level risk detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conducting a penetration test immediately before production deployment.
Why it's wrong here
Penetration testing before production is valuable, but it occurs late in the lifecycle. Finding and fixing vulnerabilities at that stage is costly and can delay releases. The goal of shifting security left is to identify issues during design and coding, so late-stage testing alone does not best support early risk identification.
- ✗
Requiring developers to complete annual secure coding training.
Why it's wrong here
Training is important for building a security culture, but it is not a real-time control. Annual training does not catch vulnerabilities in the code being written today. The most effective way to identify risks early is to automate security testing within the development workflow, providing immediate, actionable feedback on each code change.
- ✗
Performing dynamic application security testing (DAST) on a staging environment.
Why it's wrong here
DAST tests running applications and can find runtime issues, but it is typically executed later in the pipeline after the application is deployed to a test environment. While useful, it does not provide the immediate, code-level feedback that SAST offers during development, making it less effective for early risk identification.
- ✓
Integrating static application security testing (SAST) into the continuous integration pipeline.
Why this is correct
SAST tools analyze source code for security flaws as developers commit changes, providing immediate feedback. This integration into the CI pipeline embeds security into the earliest stages of development, allowing issues to be fixed before they propagate. It directly supports the DevSecOps principle of identifying and addressing risks early.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.