AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium
A team is developing a critical financial application. They need to integrate automated security testing into their CI/CD pipeline to identify common web application vulnerabilities (e.g., SQL injection, XSS) before deployment. The testing should be performed against the running application in a staging environment. Which type of automated security testing is most suitable for this requirement?
- AStatic Application Security Testing (SAST)
- BDynamic Application Security Testing (DAST)
- CSoftware Composition Analysis (SCA)
- DInteractive Application Security Testing (IAST)
Show answer & explanationAnswer & explanation
Correct answer: B. Dynamic Application Security Testing (DAST)
Dynamic Application Security Testing (DAST) analyzes the running application from the outside, simulating attacks to find vulnerabilities like SQL injection and XSS. Since the requirement is to test 'against the running application in a staging environment,' DAST is the most suitable method.
Why the other options are wrong
- A. SAST analyzes static source code or compiled binaries without executing the application. It's done earlier in the pipeline and won't detect vulnerabilities that only manifest at runtime against a deployed application.
- C. SCA focuses on identifying vulnerabilities in third-party and open-source components (dependencies), not directly on the custom code's runtime vulnerabilities like SQL injection or XSS.
- D. IAST combines elements of SAST and DAST, running within the application to analyze code execution in real-time. While effective, DAST is the more direct and commonly implemented solution for black-box testing against a running staging environment for common web vulnerabilities.
DAST (Dynamic Application Security Testing)
A security testing method that analyzes a running application to identify vulnerabilities by simulating attacks from the outside, without access to the source code.
- Tests the application in its deployed state.
- Effective for runtime vulnerabilities (e.g., XSS, SQL injection).
- Often integrated into CI/CD after deployment to a test environment.
- Black-box testing approach.
Memory trick: DAST attacks the running app to find dynamic flaws.