ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A DevOps team is building a new CI/CD pipeline for its container-based web service. Unit and functional tests already execute on every commit. Management wants any code that introduces high-severity security flaws to be rejected automatically, without waiting for manual review. Which action best enables continuous security testing that meets this objective?
Schedule an external penetration test every quarter and remediate any critical findings before the next release.
Invoke an automated static application security testing (SAST) scan on each commit and configure the build to fail if it reports high-severity issues.
Run a dynamic vulnerability scanner against the production environment each night and email reports to the security team.
Insert a manual security code review step after integration tests pass, allowing senior developers to approve merges.
Running an automated static application security test (SAST) on every code commit integrates security analysis directly into the continuous integration workflow. Because the scanner executes as part of the build job, it can automatically break the build when it detects high-severity findings, ensuring vulnerable code never progresses farther in the pipeline. Quarterly penetration tests and nightly production scans provide useful information but are not continuous or positioned early enough to stop faulty commits. A manual review gate after integration testing adds delay and still relies on human intervention rather than automation, so it does not satisfy the requirement for automatic build rejection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAST?
Open an interactive chat with Bash
How does SAST differ from DAST?
Open an interactive chat with Bash
Why is continuous security testing important in CI/CD pipelines?
Open an interactive chat with Bash
What is SAST in secure software development?
Open an interactive chat with Bash
How does SAST differ from DAST in security testing?
Open an interactive chat with Bash
What are the benefits of integrating SAST into CI/CD pipelines?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .