hardMultiple Select
CCSP Practice Question: A security team is implementing a DevSecOps…
A security team is implementing a DevSecOps pipeline for a cloud-native application. Which three practices should be included to enhance application security? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static application security testing (SAST) in CI/CD
SAST (A) is correct because it analyzes source code in the CI/CD pipeline to catch vulnerabilities like injection flaws and insecure coding patterns before the build is deployed, shifting security left. IaC scanning (B) is correct because it examines templates such as Terraform, CloudFormation, or Kubernetes manifests for misconfigurations (e.g., open S3 buckets, overly permissive IAM roles) before infrastructure is provisioned. Dependency scanning (C) is correct because it identifies known CVEs in open source libraries and transitive dependencies, which are a major attack surface in cloud-native applications, and can fail the build on critical findings. Manual penetration testing only at the final stage (D) is not a DevSecOps practice because it is late, point-in-time, and cannot keep pace with continuous delivery. RASP (E) is a runtime protection control, not a pipeline practice, and it does not prevent vulnerabilities from entering the codebase during development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static application security testing (SAST) in CI/CD
Why this is correct
SAST scans source code within the CI/CD pipeline, catching injection and insecure coding flaws before artefacts are built or deployed. This shifts detection left, satisfying the requirement to enhance security throughout the DevSecOps lifecycle rather than only at runtime.
- ✓
Infrastructure as code (IaC) scanning
Why this is correct
IaC scanning inspects Terraform, ARM or Bicep templates for misconfigurations such as public storage buckets or permissive security groups before deployment, catching flaws at the code stage rather than in running cloud infrastructure. This satisfies the pipeline's shift-left requirement by embedding security checks into version control and build automation.
- ✓
Dependency scanning for open source components
Why this is correct
Dependency scanning inventories third-party libraries and flags known CVEs in open source packages, addressing supply chain risk that cloud-native applications inherit through transitive dependencies. Integrating it into the CI/CD pipeline detects vulnerable components before build, satisfying the DevSecOps requirement to secure code artefacts continuously.
- ✗
Manual penetration testing only at final stage
Why it's wrong here
Penetration testing confined to the final stage leaves vulnerabilities undiscovered until remediation is costly and release-blocking. It is tempting because formal pen tests satisfy compliance evidence, yet they belong alongside continuous SAST, DAST and dependency scanning throughout the pipeline, not as the sole gate.
- ✗
Runtime application self-protection (RASP) deployment
Why it's wrong here
RASP instruments the running application to detect and block attacks in production, which is runtime defence rather than a pipeline build-time control. It is tempting because it adds real protection against live exploits, and it would be correct as a complementary runtime layer once shift-left scanning is already embedded.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.