Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A media company uses a CI/CD pipeline to deploy a web application to a cloud platform. The security team wants to integrate security testing that can detect vulnerabilities in third-party libraries and base images before deployment, without significantly slowing the pipeline. Which practice should be implemented?

⚠ Common exam trap

The trap here is assuming that any security testing in CI/CD covers third-party libraries and base images, when each tool type has a distinct scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Software composition analysis (SCA) and container image scanning integrated into the pipeline.

Detecting vulnerabilities in third-party libraries and base images before deployment requires tools that inspect dependencies and image contents. SCA reads dependency manifests for known CVEs, and container image scanning checks layers for vulnerable packages. Both integrate into CI/CD with fast, automated feedback. DAST and IAST need running environments and target runtime behavior, while SAST covers only first-party code, so none of those alone meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Static application security testing (SAST) on the application source code only.

    Why it's wrong here

    SAST analyzes first-party source code for flaws like injection and insecure patterns. It does not analyze third-party library versions or base image packages, so it would miss vulnerable dependencies and image components. While valuable, SAST alone does not satisfy the requirement to detect issues in libraries and base images before deployment.

  • ✓

    Software composition analysis (SCA) and container image scanning integrated into the pipeline.

    Why this is correct

    SCA examines dependency manifests and lockfiles to identify known vulnerabilities in third-party libraries, while container image scanning inspects image layers for vulnerable packages and misconfigurations. Both run early in the pipeline, provide fast feedback, and can fail builds on policy violations, meeting the requirement to detect issues before deployment without heavy slowdown.

  • ✗

    Dynamic application security testing (DAST) against the staging environment after each deployment.

    Why it's wrong here

    DAST tests a running application from the outside and can find runtime vulnerabilities, but it does not inspect third-party libraries or base image contents. It also requires a deployed environment, adding time. For detecting vulnerable dependencies and image components before deployment, DAST is the wrong tool and does not meet the pre-deployment requirement.

  • ✗

    Interactive application security testing (IAST) with agents in the staging environment.

    Why it's wrong here

    IAST instruments a running application during tests to find vulnerabilities in execution paths. It requires a deployed environment and test execution, and it does not inventory third-party libraries or base image packages. It is slower to integrate and does not address the specific goal of pre-deployment dependency and image scanning.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.