AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium

A company is developing a critical web application and needs to integrate security testing early in the development lifecycle. They want to identify potential vulnerabilities in their custom code, such as SQL injection, cross-site scripting (XSS), and insecure direct object references, before the code is even deployed or run. Which type of security testing should be integrated into their CI/CD pipeline for this purpose?

  1. ASoftware Composition Analysis (SCA).
  2. BDynamic Application Security Testing (DAST).
  3. CStatic Application Security Testing (SAST).
  4. DPenetration Testing.
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST).

Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the code. This makes it ideal for integrating early in the CI/CD pipeline to find issues like SQL injection and XSS before deployment.

Why the other options are wrong

  • A. SCA (Software Composition Analysis) focuses on identifying vulnerabilities in open-source and third-party components, not primarily in custom application code for issues like SQL injection or XSS.
  • B. DAST (Dynamic Application Security Testing) analyzes a running application, which is typically done later in the pipeline or after deployment, not 'before the code is even deployed or run'.
  • D. Penetration testing is a manual or semi-manual process typically performed on a deployed application by security experts, not an automated, early-stage CI/CD integration for every code commit.

Static Application Security Testing (SAST)

A security testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.

  • Identifies vulnerabilities early in the SDLC (Shift Left).
  • Finds issues like SQL injection, XSS, buffer overflows.
  • Can be integrated into the build stage of CI/CD.

Memory trick: For code vulnerabilities, SAST scans the source, not the running app.

More SDLC Automation questions