CCSP Cloud Application Security Practice Question
A cloud application team is adopting a DevSecOps pipeline for a containerized workload. They want to integrate security testing that can detect vulnerable dependencies and misconfigured infrastructure-as-code templates before deployment. Which two practices should be implemented to meet these goals? (Choose two.)
⚠ Common exam trap
The trap here is treating runtime defenses such as RASP or WAF as substitutes for build-time dependency and IaC scanning, when they operate at a different stage and on different artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scan infrastructure-as-code templates with a policy-as-code tool that evaluates them against organizational security baselines and blocks noncompliant changes.
Detecting vulnerable dependencies requires software composition analysis of dependency manifests during the build. Detecting misconfigured IaC requires policy-as-code scanning of templates before deployment. Both are preventive and shift security left. Runtime controls such as RASP and WAF, and dynamic testing of a running app, do not analyze dependencies or templates, so they do not meet the stated goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform dynamic application security testing against the staging environment after each deployment to find runtime vulnerabilities.
Why it's wrong here
DAST tests a running application for exploitable vulnerabilities such as injection or authentication flaws. It does not inspect dependency manifests for known CVEs or evaluate IaC templates for misconfiguration. While valuable in a DevSecOps pipeline, it addresses a different class of findings than the two stated requirements.
- ✓
Scan infrastructure-as-code templates with a policy-as-code tool that evaluates them against organizational security baselines and blocks noncompliant changes.
Why this is correct
Policy-as-code scanning of IaC templates catches misconfigurations such as public storage buckets or overly permissive security groups before resources are created. Blocking noncompliant changes enforces the baseline. This satisfies the misconfiguration detection requirement and operates early in the pipeline, preventing drift and reducing remediation cost.
- ✗
Enable runtime application self-protection in production to block exploitation attempts against the running application.
Why it's wrong here
RASP operates at runtime in production, defending against active exploitation. It does not analyze dependencies or IaC templates during the build, so it cannot detect vulnerable libraries or misconfigurations before deployment. It is a complementary control but does not meet the stated pre-deployment detection objectives.
- ✗
Deploy a web application firewall in front of the application and tune it using production traffic logs.
Why it's wrong here
A WAF filters HTTP traffic at runtime. It is unrelated to dependency vulnerability analysis and IaC template evaluation. Tuning with production logs improves protection over time but does not identify vulnerable dependencies or misconfigured infrastructure before deployment, so it does not satisfy either goal.
- ✓
Run software composition analysis (SCA) against the application's dependency manifest during the build stage and fail the build on critical findings.
Why this is correct
SCA examines declared dependencies and lockfiles against vulnerability databases, identifying known vulnerable libraries before the image is built. Failing the build on critical findings enforces remediation. This directly addresses the requirement to detect vulnerable dependencies pre-deployment and integrates cleanly into a CI pipeline as a preventive control.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.