Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy

A cybersecurity team is performing a vulnerability assessment on a new custom-developed web application. They want to identify security flaws in the application's code by analyzing it without actually executing the code. Which type of testing tool should they primarily use?

  1. AInteractive Application Security Testing (IAST)
  2. BPenetration Testing
  3. CStatic Application Security Testing (SAST)
  4. DDynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) tools analyze source code or compiled code without executing the application to find vulnerabilities, which aligns with the team's goal.

Why the other options are wrong

  • A. IAST combines elements of SAST and DAST, requiring the application to be running to provide real-time analysis.
  • B. Penetration testing is a manual process that simulates an attack on a running system, not code analysis without execution.
  • D. DAST tests the application in its running state, which is contrary to the requirement of not executing the code.

Static Application Security Testing (SAST)

A security testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the program.

  • Often performed early in the software development lifecycle (SDLC).
  • Can identify vulnerabilities like SQL injection, cross-site scripting, buffer overflows.
  • Does not require a running application.

Memory trick: Don't Just SAST and DAST, Interact for Secure Apps.

More Vulnerability Management questions