CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
An organization is developing a new mobile application that will handle sensitive customer data. To ensure the application's security, the development team plans to integrate security testing throughout the Software Development Life Cycle (SDLC). They specifically want to identify security flaws in the source code *before* the application is compiled and deployed. Which type of security testing is BEST suited for this requirement?
- AStatic Application Security Testing (SAST)
- BPenetration Testing
- CInteractive Application Security Testing (IAST)
- DDynamic Application Security Testing (DAST)
Show answer & explanationAnswer & explanation
Correct answer: A. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) is designed to analyze an application's source code, bytecode, or binary code for security vulnerabilities *before* it is compiled or executed. This directly addresses the requirement to identify flaws in the source code before deployment.
Why the other options are wrong
- B. Penetration testing is a manual, ethical hacking exercise on a deployed system, not source code analysis before deployment.
- C. IAST combines elements of SAST and DAST, testing a running application with agents to analyze code, but the core requirement is *before* compilation.
- D. DAST tests a running application and does not analyze source code directly.
Static Application Security Testing (SAST)
A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities in non-running code.
- Can find issues like buffer overflows, SQL injection (in code logic), and insecure coding practices.
Memory trick: DAST runs, SAST scans, IAST integrates, PenTest attacks – Know your app's security stance!