Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security analyst is performing a vulnerability assessment on a new web server. The analyst uses an automated tool that sends various malformed inputs and attack payloads to the running application to identify potential vulnerabilities like SQL injection and cross-site scripting. Which type of assessment is the analyst conducting?
- AStatic Application Security Testing (SAST)
- BManual Code Review
- CWhite-box Penetration Test
- DDynamic Application Security Testing (DAST)
Show answer & explanationAnswer & explanation
Correct answer: D. Dynamic Application Security Testing (DAST)
Dynamic Application Security Testing (DAST) involves testing a running application from the outside, using automated tools to simulate attacks by sending various inputs and payloads to identify runtime vulnerabilities.
Why the other options are wrong
- A. SAST analyzes code without executing the application, which is contrary to testing a 'running application'.
- B. Manual code review is a human-driven process of examining source code, not using an automated tool on a running application.
- C. While a white-box penetration test might involve DAST tools, the description focuses on the automated tool's method of testing a running application, which is characteristic of DAST, not the broader 'white-box' scope.
Dynamic Application Security Testing (DAST)
A security testing method that analyzes a running application from the outside by simulating attacks to identify runtime vulnerabilities.
- Often performed in later stages of the SDLC (test, QA, production).
- Can identify vulnerabilities like SQL injection, XSS, authentication bypass.
- Does not require access to source code.
Memory trick: Dynamic Attack Simulators Test Running Apps Externally.