CRISC Information Technology and Security Practice Question
A software development company is adopting a DevSecOps approach. The risk manager wants to ensure that security risks are identified early in the development lifecycle. Which of the following practices is MOST effective for integrating risk identification into the CI/CD pipeline?
⚠ Common exam trap
The trap here is selecting DAST or RASP because they are security testing tools, but they do not identify risks early in the development lifecycle as effectively as SAST.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct static application security testing (SAST) as part of the build process.
SAST integrated into the build process is the most effective for early risk identification because it analyzes code before it is deployed, providing immediate feedback to developers. This shift-left approach reduces the cost and effort of fixing vulnerabilities later. Other practices like DAST, manual reviews, or RASP occur later or are less scalable for continuous integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct static application security testing (SAST) as part of the build process.
Why this is correct
SAST analyzes source code or binaries for security vulnerabilities during the build phase, allowing developers to identify and fix issues early. Integrating SAST into the CI/CD pipeline automates risk identification without slowing down development. It provides immediate feedback and aligns with the shift-left approach, making it the most effective practice for early risk identification in DevSecOps.
- ✗
Perform dynamic application security testing (DAST) after deployment to production.
Why it's wrong here
DAST is typically run against running applications and is effective for finding runtime vulnerabilities, but it occurs later in the lifecycle, often after deployment. While DAST can be integrated into the pipeline against staging environments, it is not as early as SAST. The question emphasizes early identification, so SAST is more appropriate.
- ✗
Implement runtime application self-protection (RASP) in production to block attacks.
Why it's wrong here
RASP is a runtime control that detects and blocks attacks in production. It does not identify risks early in the development lifecycle; rather, it mitigates them at runtime. RASP is a compensating control, not a preventive practice for early risk identification. The goal is to shift security left, so SAST is more aligned with that objective.
- ✗
Require manual code reviews by the security team before each release.
Why it's wrong here
Manual code reviews are valuable but not scalable and often become a bottleneck in CI/CD pipelines. They may not happen early enough or frequently enough to catch all issues. While they can identify complex logic flaws, they are less effective for automated, continuous risk identification compared to SAST integrated into the build process.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.