CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A large enterprise is adopting a 'shift-left' security approach and wants to integrate security testing early into their CI/CD pipeline for custom-developed applications. The primary goal is to identify common coding vulnerabilities, such as SQL injection, cross-site scripting (XSS), and buffer overflows, before the code is even deployed. Which type of security testing tool is best suited for this objective?
- AStatic Application Security Testing (SAST)
- BSecurity Information and Event Management (SIEM)
- CPenetration Testing
- DDynamic Application Security Testing (DAST)
Show answer & explanationAnswer & explanation
Correct answer: A. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the application. This makes it ideal for integrating early in the CI/CD pipeline to find issues like SQL injection and XSS before deployment.
Why the other options are wrong
- B. SIEM is for collecting and analyzing security logs from deployed systems, not for testing code during development.
- C. Penetration testing is a manual, post-deployment activity and not suitable for automated, early-stage CI/CD integration.
- D. DAST tests applications in their running state, which is later in the development lifecycle than 'shift-left' aims for.
Static Application Security Testing (SAST)
A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Performed early in the SDLC ('shift-left').
- Identifies common coding flaws (e.g., SQLi, XSS).
- Does not require a running application.
Memory trick: SAST: 'Static Analysis Scans Text' for early bugs.