CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A large software company is adopting a 'shift-left' security approach and wants to integrate security testing into its Continuous Integration/Continuous Deployment (CI/CD) pipeline. The primary goal is to identify common security vulnerabilities and coding errors early in the development lifecycle, specifically within the source code itself, before compilation or deployment. Which security testing methodology is BEST suited for this purpose?
- ASoftware Composition Analysis (SCA).
- BStatic Application Security Testing (SAST).
- CDynamic Application Security Testing (DAST).
- DInteractive Application Security Testing (IAST).
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST).
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shifting left' by identifying vulnerabilities and coding errors early in the development process, directly from the code base before compilation or deployment.
Why the other options are wrong
- A. SCA focuses on identifying vulnerabilities in third-party and open-source components, not primarily on vulnerabilities within the custom-developed source code itself.
- C. DAST tests the application in a running state by simulating attacks, which happens later in the CI/CD pipeline, not early in the source code phase.
- D. IAST combines elements of SAST and DAST, running with the application to analyze code in real-time but still requires a running application, which is later than 'before compilation'.
Static Application Security Testing (SAST)
Static Application Security Testing (SAST) is a white-box testing method that analyzes an application's source code, bytecode, or binary code without actually executing the application, to identify security vulnerabilities and coding errors.
- Performed early in the SDLC ('shift-left').
- Identifies vulnerabilities in custom code.
- Does not require a running application.
Memory trick: SAST is like a 'spell check' for security, catching errors before you even print.