mediumMultiple Select
CCSP Practice Question: A DevSecOps team is implementing security…
A DevSecOps team is implementing security scanning in the CI/CD pipeline for a cloud application. Which THREE tools or practices should be included to shift security left?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Infrastructure-as-Code (IaC) security scanning
Infrastructure-as-Code (IaC) security scanning (A) is correct because it detects misconfigurations in templates such as Terraform, CloudFormation, or Kubernetes manifests before deployment, catching issues like open security groups or unencrypted storage early in the pipeline. Static Application Security Testing (SAST) (B) is correct because it analyzes source code without executing it to find vulnerabilities such as SQL injection or hardcoded secrets during the build phase, which is the essence of shifting security left. Dependency scanning (E), for example with Snyk, is correct because it identifies known CVEs in third-party libraries and open-source packages before they reach production, a critical early-stage control in DevSecOps. Web Application Firewall (C) deployment is not included because a WAF is a runtime, perimeter defense that filters HTTP traffic in production rather than a shift-left pipeline practice. Runtime Application Self-Protection (D) is not included because RASP instruments the running application to detect and block attacks at execution time, which is a runtime control, not an early CI/CD scanning activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Infrastructure-as-Code (IaC) security scanning
Why this is correct
IaC scanning analyses templates such as Terraform and CloudFormation before deployment, detecting misconfigured storage buckets, permissive security groups, and missing encryption. This shifts security left by catching cloud configuration flaws at code review, before infrastructure is ever provisioned.
- ✓
Static Application Security Testing (SAST)
Why this is correct
SAST examines application source code without executing it, flagging injection flaws, insecure cryptography, and hard-coded secrets during the build. Running it in the pipeline shifts security left by surfacing defects at commit time, when remediation is cheapest.
- ✗
Web Application Firewall (WAF) deployment
Why it's wrong here
A WAF filters HTTP traffic at the network edge in production, after deployment, so it cannot inspect source code, dependencies or artefacts during pipeline stages. It is tempting because it is a core application security control, but it addresses runtime threats rather than shifting detection earlier into the CI/CD pipeline.
- ✗
Runtime Application Self-Protection (RASP)
Why it's wrong here
RASP instruments a running application to detect and block attacks at execution time, which occurs in production, not during CI/CD build or commit stages. It is tempting because it is a genuine application security control, but it belongs in runtime protection alongside WAFs, not in shift-left pipeline scanning.
- ✓
Dependency scanning (e.g., Snyk)
Why this is correct
Dependency scanning inspects third-party libraries and their transitive dependencies against vulnerability databases, flagging known CVEs such as Log4Shell. Integrating it into the pipeline shifts security left by catching vulnerable components before they are packaged and deployed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.