ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A fintech start-up is building a cloud-native payment platform using an Agile Secure SDLC. During the third sprint review, penetration testers uncover several SQL injection flaws introduced by recent changes to the authentication microservice. To detect such issues earlier while maintaining rapid iterations, the security architect wants to reinforce activities that belong to the Verify (test) phase of the Secure SDLC. Which action best satisfies this requirement?

  • Integrate automated static application security testing into the CI pipeline so every code commit is scanned for flaws.

  • Deploy a web application firewall in front of the staging environment to block injection attacks during sprint demos.

  • Require developers to complete a secure-coding checklist before pushing their changes to the shared repository.

  • Conduct threat-modeling workshops during backlog refinement to identify potential attack paths.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot