CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
A development team wants to test a running web application for vulnerabilities without access to its source code, simulating how an external attacker would interact with it over HTTP. Which testing approach should they use?
- AStatic Application Security Testing (SAST)
- BManual source code peer review
- CDynamic Application Security Testing (DAST)
- DSoftware Composition Analysis (SCA)
Show answer & explanationAnswer & explanation
Correct answer: C. Dynamic Application Security Testing (DAST)
DAST is a black-box testing technique that examines a running application from the outside, sending crafted inputs over HTTP without requiring access to source code — exactly matching the scenario's requirement.
Why the other options are wrong
- A. SAST is white-box testing that analyzes source code, bytecode, or binaries directly, requiring code access.
- B. Manual code review requires direct access to and reading of the source code.
- D. SCA analyzes third-party/open-source library dependencies for known vulnerabilities, not runtime behavior testing.
DAST (Dynamic Application Security Testing)
A black-box testing method that probes a running application externally (e.g., via HTTP requests) to find vulnerabilities without needing source code access.
- Also called black-box testing
- Finds runtime issues like injection, auth flaws, XSS
- Contrasts with SAST, which is white-box source code analysis
Memory trick: DAST = Doing it from the Outside; SAST = Seeing All the Source Text.