ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a pre-release review, your team must uncover security flaws in a Java microservice by scanning its source code inside the CI pipeline. The service will not be executed during the scan. Which approach should you employ?
Interactive application security testing executed during automated functional tests
Dynamic application security testing against a running container in staging
Static application security testing integrated with linting rules during the build
Black-box penetration testing of the staging environment after deployment
Static application security testing (SAST) is a white-box technique that inspects source, bytecode, or binaries without running the program, making it ideal for CI pipelines that need early detection of issues such as SQL injection or insecure deserialization before deployment. Dynamic and interactive testing, as well as black-box penetration tests, all require the application to execute in a running environment, so they do not meet the requirement of performing analysis without launching the service.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Static Application Security Testing (SAST)?
Open an interactive chat with Bash
How does SAST differ from Dynamic Application Security Testing (DAST)?
Open an interactive chat with Bash
What are linting rules, and how do they assist in security testing?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .