Courseiva
mediumMultiple Select

CCSP Practice Question: A DevSecOps team is implementing security…

A DevSecOps team is implementing security scanning in the CI/CD pipeline for a cloud application. Which THREE tools or practices should be included to shift security left?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Infrastructure-as-Code (IaC) security scanning

Infrastructure-as-Code (IaC) security scanning (A) is correct because it detects misconfigurations in templates such as Terraform, CloudFormation, or Kubernetes manifests before deployment, catching issues like open security groups or unencrypted storage early in the pipeline. Static Application Security Testing (SAST) (B) is correct because it analyzes source code without executing it to find vulnerabilities such as SQL injection or hardcoded secrets during the build phase, which is the essence of shifting security left. Dependency scanning (E), for example with Snyk, is correct because it identifies known CVEs in third-party libraries and open-source packages before they reach production, a critical early-stage control in DevSecOps. Web Application Firewall (C) deployment is not included because a WAF is a runtime, perimeter defense that filters HTTP traffic in production rather than a shift-left pipeline practice. Runtime Application Self-Protection (D) is not included because RASP instruments the running application to detect and block attacks at execution time, which is a runtime control, not an early CI/CD scanning activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Infrastructure-as-Code (IaC) security scanning

    Why this is correct

    IaC scanning analyses templates such as Terraform and CloudFormation before deployment, detecting misconfigured storage buckets, permissive security groups, and missing encryption. This shifts security left by catching cloud configuration flaws at code review, before infrastructure is ever provisioned.

  • ✓

    Static Application Security Testing (SAST)

    Why this is correct

    SAST examines application source code without executing it, flagging injection flaws, insecure cryptography, and hard-coded secrets during the build. Running it in the pipeline shifts security left by surfacing defects at commit time, when remediation is cheapest.

  • ✗

    Web Application Firewall (WAF) deployment

    Why it's wrong here

    A WAF filters HTTP traffic at the network edge in production, after deployment, so it cannot inspect source code, dependencies or artefacts during pipeline stages. It is tempting because it is a core application security control, but it addresses runtime threats rather than shifting detection earlier into the CI/CD pipeline.

  • ✗

    Runtime Application Self-Protection (RASP)

    Why it's wrong here

    RASP instruments a running application to detect and block attacks at execution time, which occurs in production, not during CI/CD build or commit stages. It is tempting because it is a genuine application security control, but it belongs in runtime protection alongside WAFs, not in shift-left pipeline scanning.

  • ✓

    Dependency scanning (e.g., Snyk)

    Why this is correct

    Dependency scanning inspects third-party libraries and their transitive dependencies against vulnerability databases, flagging known CVEs such as Log4Shell. Integrating it into the pipeline shifts security left by catching vulnerable components before they are packaged and deployed.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.