AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium

A company is developing a serverless application using AWS Lambda and Amazon API Gateway. They need to ensure that their CI/CD pipeline automatically includes security scans for common vulnerabilities in their Lambda function code before deployment. The scans should be fast and integrate seamlessly into their build process. Which security testing approach is most suitable for this requirement?

  1. ADynamic Application Security Testing (DAST) on the deployed application.
  2. BManual code review by a security expert.
  3. CStatic Application Security Testing (SAST) during the build phase.
  4. DPenetration testing on the production environment.
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST) during the build phase.

Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application. It's ideal for integrating into the build phase of a CI/CD pipeline, providing fast feedback on code-level issues before deployment.

Why the other options are wrong

  • A. DAST runs on a deployed application, which is too late for 'before deployment' and slower than SAST.
  • B. Manual code review is not automated and cannot be seamlessly integrated into an automatic CI/CD pipeline for every build.
  • D. Penetration testing is a post-deployment activity, too late for 'before deployment' and not automated for every build.

Static Application Security Testing (SAST)

A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.

  • Performed early in the SDLC (e.g., during development or build).
  • Identifies vulnerabilities at the code level (e.g., SQL injection, XSS).
  • Provides fast feedback to developers.
  • Integrates well with CI/CD pipelines.

Memory trick: SAST: Scan the code, catch bugs before they run.

More SDLC Automation questions