CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A development team is building a new mobile application that will handle sensitive customer data. They want to identify security vulnerabilities such as hardcoded credentials, insecure configuration, and potential injection flaws early in the development lifecycle, without actually running the application. Which testing methodology is best suited for this purpose?

  1. ADynamic Application Security Testing (DAST)
  2. BStatic Application Security Testing (SAST)
  3. CInteractive Application Security Testing (IAST)
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: B. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code without executing it. This allows for the identification of vulnerabilities such as hardcoded credentials, insecure configurations, and injection flaws early in the SDLC, aligning perfectly with the requirement to find flaws 'without actually running the application'.

Why the other options are wrong

  • A. DAST tests a running application by simulating attacks, which contradicts the 'without running the application' requirement.
  • C. IAST combines elements of SAST and DAST, requiring the application to be running in a test environment.
  • D. SCA identifies known vulnerabilities in third-party and open-source components, but it doesn't analyze custom code for secure coding practices.

Static Application Security Testing (SAST)

SAST is a white-box testing methodology that analyzes an application's source code, bytecode, or binary code for vulnerabilities without executing the application.

  • Identifies flaws early in the Software Development Lifecycle (SDLC).
  • Can find issues like injection flaws, hardcoded credentials, and insecure configurations.
  • Does not require a running application, making it suitable for developers.

Memory trick: SAST: Static, Analyze Source – looks at the 'static' code, not running 'app'.

More Vulnerability Management questions