CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A development team wants to test a running web application for vulnerabilities without access to its source code, simulating how an external attacker would interact with it over HTTP. Which testing approach should they use?

  1. AStatic Application Security Testing (SAST)
  2. BManual source code peer review
  3. CDynamic Application Security Testing (DAST)
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: C. Dynamic Application Security Testing (DAST)

DAST is a black-box testing technique that examines a running application from the outside, sending crafted inputs over HTTP without requiring access to source code — exactly matching the scenario's requirement.

Why the other options are wrong

  • A. SAST is white-box testing that analyzes source code, bytecode, or binaries directly, requiring code access.
  • B. Manual code review requires direct access to and reading of the source code.
  • D. SCA analyzes third-party/open-source library dependencies for known vulnerabilities, not runtime behavior testing.

DAST (Dynamic Application Security Testing)

A black-box testing method that probes a running application externally (e.g., via HTTP requests) to find vulnerabilities without needing source code access.

  • Also called black-box testing
  • Finds runtime issues like injection, auth flaws, XSS
  • Contrasts with SAST, which is white-box source code analysis

Memory trick: DAST = Doing it from the Outside; SAST = Seeing All the Source Text.

More Vulnerability Management questions