CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to integrate security testing as early as possible in the development lifecycle to identify and remediate vulnerabilities before deployment. Which security tool or practice is MOST aligned with this 'shift-left' strategy at the code development stage?
- APenetration Testing
- BStatic Application Security Testing (SAST)
- CDynamic Application Security Testing (DAST)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) tools analyze source code, bytecode, or binary code for security vulnerabilities without executing the application. This allows developers to find and fix issues early in the development cycle, immediately after writing code, which is the essence of 'shift-left' security.
Why the other options are wrong
- A. Penetration testing is typically performed on a fully developed and deployed application, often in staging or production, and is not an early-stage development activity.
- C. DAST tests a running application in a dynamic state, typically later in the SDLC (e.g., QA or staging), which is not 'shift-left' to the code development stage.
- D. A SIEM is used for real-time security monitoring and incident response in production environments, far beyond the development stage.
Static Application Security Testing (SAST)
SAST is a white-box testing methodology that analyzes an application's source code, bytecode, or binary code to detect security vulnerabilities without executing the application. It's used early in the SDLC.
- Analyzes code without execution.
- Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
- Used early in the Software Development Life Cycle (SDLC).
- Helps developers fix issues before they become expensive to remediate.
Memory trick: To fix bugs early, you need to see the code, not just run it.