Courseiva

CISSP Software Development Security Practice Question

A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?

⚠ Common exam trap

Many exam-takers confuse DAST with other testing methods like SAST or IAST, which do not simulate external attacks against a running application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic Application Security Testing (DAST)

Dynamic Application Security Testing (DAST) is designed to simulate real-world attacks by testing a running application from the outside. It identifies vulnerabilities that manifest at runtime, such as input validation errors and authentication flaws. Unlike SAST or SCA, DAST actively probes the application as an attacker would, making it the appropriate choice for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Dynamic Application Security Testing (DAST)

    Why this is correct

    DAST tests a running application from the outside, simulating attacks similar to those a real attacker would use. It can identify vulnerabilities such as injection, authentication flaws, and misconfigurations that only appear at runtime. This directly meets the requirement to test for security vulnerabilities by simulating real-world attacks against the deployed application.

  • ✗

    Interactive Application Security Testing (IAST)

    Why it's wrong here

    IAST combines elements of SAST and DAST by instrumenting the application during runtime, often in a test environment. While it can detect vulnerabilities with high accuracy, it requires agents and may not fully simulate external attacks. It is not primarily designed to mimic real-world attacker behavior from an external perspective.

  • ✗

    Static Application Security Testing (SAST)

    Why it's wrong here

    SAST analyzes source code or binaries without executing the application. It is effective for finding coding flaws early but does not simulate real-world attacks against a running system. It cannot detect runtime or configuration issues that a dynamic test would reveal, making it less suited for this requirement.

  • ✗

    Software Composition Analysis (SCA)

    Why it's wrong here

    SCA identifies known vulnerabilities in third-party components and libraries. While important, it does not simulate attacks against the application itself. It focuses on dependency risks rather than the application's runtime behavior, so it does not fulfill the requirement for attack simulation.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.