CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to identify and remediate security vulnerabilities in their custom-developed code as early as possible, ideally before the code is even compiled or deployed. Which security testing tool is best suited for this objective?

  1. AStatic Application Security Testing (SAST)
  2. BInteractive Application Security Testing (IAST)
  3. CDynamic Application Security Testing (DAST)
  4. DPenetration Testing
Show answer & explanation

Correct answer: A. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shift-left' as it can identify vulnerabilities early in the development lifecycle, even before the application is compiled or deployed, aligning with the goal of early detection.

Why the other options are wrong

  • B. IAST combines SAST and DAST by analyzing the application dynamically from within, requiring the application to be running, which is not 'before compilation'.
  • C. DAST tests a running application and is typically used later in the development cycle, not 'before the code is even compiled'.
  • D. Penetration Testing is a manual, expert-driven process on a deployed application, making it a late-stage activity, not suitable for early detection in the CI/CD pipeline.

Static Application Security Testing (SAST)

A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Identifies vulnerabilities early in the SDLC ('shift-left').
  • Can be integrated into IDEs and CI/CD pipelines.
  • Does not require a running application.

Memory trick: App security testing is like checking a car: some check blueprints (SAST), some check it running (DAST), some drive it hard (pen test).

More Security Architecture questions