ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is adding a security "quality gate" to its continuous integration (CI) pipeline. The gate must automatically analyze every source-code commit for vulnerabilities, fail the build if issues are found, and give developers file-and-line references before the code is compiled or executed. Which technique best satisfies these requirements?
Schedule manual penetration tests before each planned release to staging.
Integrate a static application security testing (SAST) scanner into the CI workflow.
Enable a runtime application self-protection (RASP) agent in the production environment.
Run a dynamic application security testing (DAST) suite against the built application in a test environment.
Static application security testing (SAST) examines source code, byte-code, or binaries without running the application. Because analysis occurs pre-compile or during the build, SAST can be invoked on each commit, integrate with IDE or CI tools, and report precise file-and-line locations so developers can correct problems immediately. Dynamic application security testing requires a running instance, so it cannot block a compile-time gate. Runtime application self-protection operates only after deployment, and manual penetration testing is too late-stage and slow for every commit. Therefore, integrating a SAST scanner is the only option that meets all stated criteria.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAST and how does it work?
Open an interactive chat with Bash
How does SAST differ from DAST?
Open an interactive chat with Bash
Why can SAST be used as a quality gate in CI pipelines?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .