CISSP Software Development Security Practice Question
A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?
⚠ Common exam trap
Many exam-takers confuse DAST with other testing methods like SAST or IAST, which do not simulate external attacks against a running application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Application Security Testing (DAST)
Dynamic Application Security Testing (DAST) is designed to simulate real-world attacks by testing a running application from the outside. It identifies vulnerabilities that manifest at runtime, such as input validation errors and authentication flaws. Unlike SAST or SCA, DAST actively probes the application as an attacker would, making it the appropriate choice for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dynamic Application Security Testing (DAST)
Why this is correct
DAST tests a running application from the outside, simulating attacks similar to those a real attacker would use. It can identify vulnerabilities such as injection, authentication flaws, and misconfigurations that only appear at runtime. This directly meets the requirement to test for security vulnerabilities by simulating real-world attacks against the deployed application.
- ✗
Interactive Application Security Testing (IAST)
Why it's wrong here
IAST combines elements of SAST and DAST by instrumenting the application during runtime, often in a test environment. While it can detect vulnerabilities with high accuracy, it requires agents and may not fully simulate external attacks. It is not primarily designed to mimic real-world attacker behavior from an external perspective.
- ✗
Static Application Security Testing (SAST)
Why it's wrong here
SAST analyzes source code or binaries without executing the application. It is effective for finding coding flaws early but does not simulate real-world attacks against a running system. It cannot detect runtime or configuration issues that a dynamic test would reveal, making it less suited for this requirement.
- ✗
Software Composition Analysis (SCA)
Why it's wrong here
SCA identifies known vulnerabilities in third-party components and libraries. While important, it does not simulate attacks against the application itself. It focuses on dependency risks rather than the application's runtime behavior, so it does not fulfill the requirement for attack simulation.
Go deeper
Related to this question
Learn chapter
Software Development Security
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.