Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security team is performing a comprehensive vulnerability assessment of a new cloud-native application. They want to identify vulnerabilities that are present during runtime, specifically focusing on how the application interacts with external inputs and services. Which type of testing is BEST suited for this purpose?

  1. AStatic Application Security Testing (SAST)
  2. BManual Code Review
  3. CSoftware Composition Analysis (SCA)
  4. DDynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: D. Dynamic Application Security Testing (DAST)

Dynamic Application Security Testing (DAST) analyzes applications while they are running, interacting with them as an attacker would. This makes it ideal for identifying runtime vulnerabilities related to external inputs and services, which SAST and SCA typically miss.

Why the other options are wrong

  • A. SAST analyzes code without running it, missing runtime interactions and external input issues.
  • B. Manual code review is thorough but is a static analysis and may not fully reveal runtime interaction issues efficiently.
  • C. SCA identifies vulnerabilities in third-party and open-source components, not runtime interaction issues.

Dynamic Application Security Testing (DAST)

DAST is a black-box testing method that analyzes a running application from the outside, simulating attacks to find vulnerabilities that manifest during runtime.

  • Identifies vulnerabilities that are only apparent when the application is running.
  • Does not require access to source code.
  • Effective for finding issues related to external inputs, configuration, and interactions with other services.

Memory trick: DAST Runs, SAST Reads, SCA Checks Libraries.

More Vulnerability Management questions