Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud development team is adopting a DevSecOps approach for their new microservices project. They want to integrate security testing early and continuously into their CI/CD pipeline. Which type of security testing is most effective for identifying vulnerabilities in custom code during the build phase before deployment to a staging environment?
- AVulnerability Scanning (VS)
- BDynamic Application Security Testing (DAST)
- CPenetration Testing (PT)
- DStatic Application Security Testing (SAST)
Show answer & explanationAnswer & explanation
Correct answer: D. Static Application Security Testing (SAST)
SAST analyzes source code, bytecode, or binary code for security vulnerabilities without executing the application, making it ideal for the build phase of a CI/CD pipeline.
Why the other options are wrong
- A. Vulnerability scanning typically focuses on known vulnerabilities in infrastructure components or dependencies, rather than custom application code during the build phase.
- B. DAST tests a running application by attacking it from the outside, which occurs after the build phase, usually in a test or staging environment.
- C. Penetration testing is typically performed on a running application in a production or pre-production environment, not during the build phase.
Static Application Security Testing (SAST)
SAST is a white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (build phase).
- Identifies vulnerabilities in custom code.
- Does not require a running application.
Memory trick: DevSecOps testing: SAST is 'Source Analysis', DAST is 'Dynamic Attack'.