Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security analyst is conducting a vulnerability assessment on a new custom-developed web application. The analyst wants to identify potential weaknesses in the application's source code before it is deployed to production. Which type of testing would be most effective for this purpose?
- AVulnerability Scanning
- BStatic Application Security Testing (SAST)
- CDynamic Application Security Testing (DAST)
- DPenetration Testing
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) directly analyzes the application's source code without executing it, making it ideal for identifying vulnerabilities early in the development lifecycle before deployment. DAST and penetration testing require a running application, while general vulnerability scanning typically focuses on network and system-level weaknesses.
Why the other options are wrong
- A. Vulnerability scanning typically focuses on network services and system configurations, not the internal source code of an application.
- C. DAST analyzes a running application from the outside, not the source code directly.
- D. Penetration testing involves exploiting vulnerabilities in a running system, which is not the primary goal for pre-deployment source code analysis.
Static Application Security Testing (SAST)
A white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program.
- Performed early in the SDLC (shift-left)
- Identifies vulnerabilities in custom code
- Does not require a running application
Memory trick: Static Code Finds Bugs Early, Dynamic Explores Running Apps.