CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to identify and remediate security vulnerabilities in their custom-developed code as early as possible, ideally before the code is even compiled or deployed. Which security testing tool is best suited for this objective?
- AStatic Application Security Testing (SAST)
- BInteractive Application Security Testing (IAST)
- CDynamic Application Security Testing (DAST)
- DPenetration Testing
Show answer & explanationAnswer & explanation
Correct answer: A. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shift-left' as it can identify vulnerabilities early in the development lifecycle, even before the application is compiled or deployed, aligning with the goal of early detection.
Why the other options are wrong
- B. IAST combines SAST and DAST by analyzing the application dynamically from within, requiring the application to be running, which is not 'before compilation'.
- C. DAST tests a running application and is typically used later in the development cycle, not 'before the code is even compiled'.
- D. Penetration Testing is a manual, expert-driven process on a deployed application, making it a late-stage activity, not suitable for early detection in the CI/CD pipeline.
Static Application Security Testing (SAST)
A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Identifies vulnerabilities early in the SDLC ('shift-left').
- Can be integrated into IDEs and CI/CD pipelines.
- Does not require a running application.
Memory trick: App security testing is like checking a car: some check blueprints (SAST), some check it running (DAST), some drive it hard (pen test).