AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium
A company wants to introduce security scanning into their CI/CD pipeline for a Java application. They need to analyze their source code for common vulnerabilities and coding flaws before the build stage. The scan should be automated and provide actionable feedback to developers. Which type of security testing should be integrated into the pipeline at this early stage?
- ADynamic Application Security Testing (DAST).
- BStatic Application Security Testing (SAST).
- CInteractive Application Security Testing (IAST).
- DSoftware Composition Analysis (SCA).
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST).
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the application. It is ideal for integration early in the CI/CD pipeline, often before or during the build stage, to provide fast feedback to developers on coding flaws.
Why the other options are wrong
- A. DAST scans a running application, which occurs later in the pipeline, not before the build stage.
- C. IAST combines elements of SAST and DAST, running during application execution, which is not 'before the build stage'.
- D. SCA identifies vulnerabilities in third-party and open-source components, which is important but distinct from analyzing custom source code for coding flaws.
Static Application Security Testing (SAST)
A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities like SQL injection, cross-site scripting (XSS).
- Can be integrated into IDEs and CI/CD pipelines.
Memory trick: SAST is like a meticulous librarian, checking every book (code) before it's even opened.