Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A cybersecurity team is performing a comprehensive vulnerability assessment of a new cloud-native application. They want to identify security flaws that might only become apparent when the application is actively running and interacting with its environment. Which testing method is best suited for this purpose?

  1. ADynamic Application Security Testing (DAST)
  2. BManual Code Review
  3. CStatic Application Security Testing (SAST)
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: A. Dynamic Application Security Testing (DAST)

Dynamic Application Security Testing (DAST) analyzes a running application from the outside, simulating attacks to find vulnerabilities that are only detectable during execution, such as misconfigurations, runtime errors, or issues with authentication and session management. This directly addresses the need to find flaws 'when the application is actively running'.

Why the other options are wrong

  • B. Manual code review analyzes source code but is typically done statically and might miss complex runtime interactions.
  • C. SAST analyzes source code without running the application, missing runtime issues.
  • D. SCA focuses on identifying vulnerabilities in third-party components, not runtime application logic.

Dynamic Application Security Testing (DAST)

A black-box testing methodology that analyzes a running application from the outside to identify vulnerabilities by simulating attacks and observing application behavior.

  • Detects runtime vulnerabilities (e.g., authentication, session management, misconfigurations).
  • Does not require access to source code.
  • Identifies issues that only appear during execution.

Memory trick: Dynamic runs to find runtime flaws.

More Vulnerability Management questions