Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security team is considering adopting a new approach to vulnerability assessment that focuses on identifying security flaws early in the software development lifecycle, before deployment to production. This approach aims to reduce the cost and effort of fixing vulnerabilities. Which of the following assessment types aligns with this strategy?

  1. ADynamic Application Security Testing (DAST)
  2. BStatic Application Security Testing (SAST)
  3. CRuntime Application Self-Protection (RASP)
  4. DPenetration Testing
Show answer & explanation

Correct answer: B. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application, making it ideal for identifying vulnerabilities early in the software development lifecycle (SDLC) during the coding phase.

Why the other options are wrong

  • A. DAST tests applications in their running state, typically after deployment, which is later in the SDLC.
  • C. RASP is a security technology that protects applications at runtime, not an assessment type for early identification.
  • D. Penetration testing is typically performed on a deployed application to simulate real-world attacks, which is late in the SDLC.

Static Application Security Testing (SAST)

A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application. It is typically performed early in the SDLC.

  • Analyzes code without execution.
  • Identifies vulnerabilities early in the SDLC (Shift-Left).
  • Can find issues like SQL injection, buffer overflows, and cross-site scripting (XSS).

Memory trick: To secure code efficiently, test it 'static' and 'dynamic' during development, and 'penetrate' when it's live.

More Vulnerability Management questions