Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy

A cloud application development team is adopting a DevSecOps approach. They want to integrate security testing into their Continuous Integration/Continuous Delivery (CI/CD) pipeline to identify vulnerabilities early in the development lifecycle. Which type of security testing is BEST suited for automatically analyzing source code for potential vulnerabilities without executing the application?

  1. ADynamic Application Security Testing (DAST).
  2. BStatic Application Security Testing (SAST).
  3. CInteractive Application Security Testing (IAST).
  4. DPenetration Testing.
Show answer & explanation

Correct answer: B. Static Application Security Testing (SAST).

Static Application Security Testing (SAST) is designed to analyze application source code, bytecode, or binary code for security vulnerabilities without actually executing the application. It's ideal for integrating into CI/CD pipelines as it can run early and automatically.

Why the other options are wrong

  • A. DAST tests a running application by attacking it from the outside, which is not 'without executing the application'.
  • C. IAST combines elements of SAST and DAST, requiring the application to be running to observe its behavior.
  • D. Penetration testing is a manual or semi-manual process performed on a running application, not an automated, non-execution analysis of source code.

Static Application Security Testing (SAST)

A white-box testing methodology that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application. It identifies flaws early in the SDLC.

  • Analyzes code without execution.
  • Identifies vulnerabilities in early development stages.
  • Can be integrated into CI/CD pipelines.

Memory trick: It's like having a meticulous proofreader check every line of code before the book is even printed.

More Cloud Application Security questions