CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A development team wants to identify vulnerabilities such as hardcoded credentials, insecure cryptographic calls, and unsafe deserialization directly within the application's source code before it is compiled or deployed. Which testing technique best fits this requirement?
- AFuzzing
- BSAST
- CPenetration testing
- DDAST
Show answer & explanationAnswer & explanation
Correct answer: B. SAST
Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, allowing detection of coding flaws like hardcoded secrets early in the SDLC. DAST requires a running application, and fuzzing/pen testing operate against runtime behavior rather than static code.
Why the other options are wrong
- A. Fuzzing sends malformed input to a running program to trigger crashes, not a code review technique.
- C. Penetration testing typically targets a deployed system, not raw source code.
- D. DAST tests a running application from the outside, not the source code.
SAST (Static Application Security Testing)
SAST analyzes application source code, bytecode, or binaries without executing the program to find security flaws early in development.
- Performed early in SDLC (shift-left)
- Finds issues like hardcoded secrets and insecure API usage
- Complementary to DAST which tests running applications
Memory trick: SAST reads the recipe (code); DAST tastes the dish (running app)