Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security analyst is performing a vulnerability assessment on a new web server. The analyst uses an automated tool that sends various malformed inputs and attack payloads to the running application to identify potential vulnerabilities like SQL injection and cross-site scripting. Which type of assessment is the analyst conducting?

  1. AStatic Application Security Testing (SAST)
  2. BManual Code Review
  3. CWhite-box Penetration Test
  4. DDynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: D. Dynamic Application Security Testing (DAST)

Dynamic Application Security Testing (DAST) involves testing a running application from the outside, using automated tools to simulate attacks by sending various inputs and payloads to identify runtime vulnerabilities.

Why the other options are wrong

  • A. SAST analyzes code without executing the application, which is contrary to testing a 'running application'.
  • B. Manual code review is a human-driven process of examining source code, not using an automated tool on a running application.
  • C. While a white-box penetration test might involve DAST tools, the description focuses on the automated tool's method of testing a running application, which is characteristic of DAST, not the broader 'white-box' scope.

Dynamic Application Security Testing (DAST)

A security testing method that analyzes a running application from the outside by simulating attacks to identify runtime vulnerabilities.

  • Often performed in later stages of the SDLC (test, QA, production).
  • Can identify vulnerabilities like SQL injection, XSS, authentication bypass.
  • Does not require access to source code.

Memory trick: Dynamic Attack Simulators Test Running Apps Externally.

More Vulnerability Management questions