ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A SaaS development team has moved from a waterfall model to two-week agile sprints and now releases new container images multiple times per week. The cloud security architect notices that regulatory security requirements that were once verified in the dedicated test phase are no longer being consistently met. Which action best aligns security testing with the new SDLC methodology without slowing delivery?
Defer all vulnerability scanning to the maintenance phase to avoid impacting sprint velocity.
Hold a single security design review meeting at project kickoff and reuse the resulting document for the rest of the release cycle.
Integrate automated static application security testing into the CI pipeline so it runs on every code commit during each sprint.
Schedule a comprehensive external penetration test only after the minimum viable product is in production.
Automated static application security testing (SAST) integrated into the continuous-integration (CI) pipeline runs every time developers commit code, so it fits naturally into short agile iterations. It gives rapid feedback before code is merged, helping the team meet security requirements in each sprint. A single penetration test after the MVP, a one-time design review, or postponing scans to maintenance all recreate a late, waterfall-style test phase and allow insecure code to reach production between tests.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Static Application Security Testing (SAST)?
Open an interactive chat with Bash
What is a CI pipeline, and how does it support agile development?
Open an interactive chat with Bash
Why does agile development require different security practices than the waterfall model?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .