Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A software development team is adopting a 'shift-left' security approach to identify vulnerabilities earlier in the development lifecycle. Which type of tool would be most effective for automatically analyzing source code for potential security flaws *before* the application is even compiled or deployed?

  1. ARuntime Application Self-Protection (RASP)
  2. BDynamic Application Security Testing (DAST)
  3. CStatic Application Security Testing (SAST)
  4. DPenetration Testing
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) tools analyze application source code, bytecode, or binary code for security vulnerabilities without actually executing the application. This makes them ideal for 'shift-left' strategies, catching issues early in development.

Why the other options are wrong

  • A. RASP protects applications in runtime by instrumenting them, not by analyzing source code pre-deployment.
  • B. DAST tools analyze running applications, not source code before compilation.
  • D. Penetration testing involves ethical hacking against a running system, not source code analysis.

Static Application Security Testing (SAST)

A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Identifies vulnerabilities early in the software development lifecycle (SDLC).
  • Does not require a running application.
  • Can detect issues like SQL injection, cross-site scripting, and buffer overflows in code.

Memory trick: Static code, Dynamic runs, RASP protects, Pen tests hack.

More Vulnerability Management questions