ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During sprint 8, a Scrum team discovers that their CI/CD pipeline still deploys container images even when the integrated static application security testing (SAST) tool flags new high-severity findings in recently committed code. To embed security more effectively without introducing significant delays to their two-week release cycle, which process change should the team implement?
Track SAST results in sprint retrospectives and schedule remediation tasks for later iterations.
Shift SAST scanning to a quarterly third-party penetration test and address findings in bulk.
Configure the pipeline to fail any build that introduces a new high-severity SAST finding, blocking the merge until the issue is fixed.
Keep the current automation but mandate that the security team performs manual code reviews after every successful build.
In a DevSecOps environment, security checks must be automated and decisive. Configuring the CI/CD pipeline to halt ("break") the build whenever the SAST scanner reports new high-severity vulnerabilities enforces an immediate feedback loop: developers must remediate critical issues before code can be merged or deployed. This integrates security into the existing Agile workflow with minimal manual overhead.
Moving SAST to a quarterly penetration test postpones feedback and contradicts continuous security principles.
Deferring discussion to retrospectives logs the issue but does not stop vulnerable code from reaching production.
Adding mandatory manual reviews for every commit significantly slows delivery and may still miss issues that automated tools detect instantly.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a CI/CD pipeline?
Open an interactive chat with Bash
What is Static Application Security Testing (SAST)?
Open an interactive chat with Bash
Why should a high-severity finding block the CI/CD pipeline?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .