Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium

A cloud development team is adopting a DevSecOps approach for their new microservices project. They want to integrate security testing early and continuously into their CI/CD pipeline. Which type of security testing is most effective for identifying vulnerabilities in custom code during the build phase before deployment to a staging environment?

  1. AVulnerability Scanning (VS)
  2. BDynamic Application Security Testing (DAST)
  3. CPenetration Testing (PT)
  4. DStatic Application Security Testing (SAST)
Show answer & explanation

Correct answer: D. Static Application Security Testing (SAST)

SAST analyzes source code, bytecode, or binary code for security vulnerabilities without executing the application, making it ideal for the build phase of a CI/CD pipeline.

Why the other options are wrong

  • A. Vulnerability scanning typically focuses on known vulnerabilities in infrastructure components or dependencies, rather than custom application code during the build phase.
  • B. DAST tests a running application by attacking it from the outside, which occurs after the build phase, usually in a test or staging environment.
  • C. Penetration testing is typically performed on a running application in a production or pre-production environment, not during the build phase.

Static Application Security Testing (SAST)

SAST is a white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Performed early in the SDLC (build phase).
  • Identifies vulnerabilities in custom code.
  • Does not require a running application.

Memory trick: DevSecOps testing: SAST is 'Source Analysis', DAST is 'Dynamic Attack'.

More Cloud Application Security questions