CompTIA SecurityX (CAS-005)Security EngineeringMedium

A software development team is adopting a DevOps methodology and needs to integrate security practices throughout their continuous integration/continuous deployment (CI/CD) pipeline. They want to automate security checks as much as possible to ensure rapid feedback and maintain development velocity. Which security automation tool is MOST appropriate for identifying potential vulnerabilities in the source code BEFORE deployment?

  1. ASecurity Information and Event Management (SIEM) system
  2. BDynamic Application Security Testing (DAST) tool
  3. CStatic Application Security Testing (SAST) tool
  4. DNetwork Intrusion Prevention System (NIPS)
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST) tool

SAST tools analyze source code, bytecode, or binary code for security vulnerabilities without executing the application. This makes them ideal for integration into CI/CD pipelines to provide early feedback to developers before deployment.

Why the other options are wrong

  • A. A SIEM system collects and analyzes security logs and events from various sources, primarily for post-deployment monitoring and incident response, not pre-deployment code analysis.
  • B. DAST tools test applications in their running state by simulating attacks, typically used later in the development lifecycle or post-deployment, not for source code analysis before deployment.
  • D. NIPS monitors network traffic for malicious activity and attempts to block it, operating at the network level and not involved in code analysis.

Static Application Security Testing (SAST)

A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Analyzes code without execution.
  • Identifies vulnerabilities early in the SDLC.
  • Often integrated into CI/CD pipelines.

Memory trick: SAST for the code, DAST for the running app.

More Security Engineering questions