CCSP Cloud Application Security Practice Question
A DevSecOps team is integrating static application security testing (SAST) into their CI/CD pipeline. Which of the following is the PRIMARY benefit of performing SAST during the build phase rather than later in the pipeline?
⚠ Common exam trap
ISC2 often tests the concept of 'shift left' security, and the trap here is confusing SAST's static analysis capability with runtime detection, leading candidates to incorrectly choose options that describe dynamic or runtime testing benefits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables early detection of vulnerabilities before deployment
Performing SAST during the build phase allows the team to identify security vulnerabilities in the source code before the application is compiled, packaged, or deployed. This early detection reduces the cost and effort of remediation because issues are found at the point of code creation, not after deployment. The primary benefit is shifting security left to catch defects before they reach production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It identifies runtime vulnerabilities such as SQL injection
Why it's wrong here
SAST inspects source or bytecode without executing it, so it cannot observe runtime behaviour such as SQL injection, which requires a running application and dynamic testing. It is tempting because SAST does flag injection-prone coding patterns statically, but confirming exploitability at runtime is DAST's role.
- ✗
It reduces false positives compared to dynamic analysis
Why it's wrong here
SAST's earlier placement in the build phase does not reduce false positives; static analysis typically produces more than dynamic testing because it lacks runtime context. It is tempting because shifting checks left is genuinely valuable, but the benefit is earlier, cheaper remediation, not improved accuracy.
- ✓
It enables early detection of vulnerabilities before deployment
Why this is correct
SAST analyses source code during the build, so flaws are flagged in the commit that introduced them, before artefacts reach staging or production. This shifts remediation left, cutting the cost and risk of fixing defects after deployment, which is the stem's stated build-phase constraint.
- ✗
It scans running applications to find configuration issues
Why it's wrong here
SAST analyses source code or compiled artefacts without executing them, so it cannot scan running applications or detect live configuration issues; that is dynamic analysis or configuration scanning. It is tempting because runtime misconfiguration is a real risk, but SAST operates before deployment, not against a live instance.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.