CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
An organization is developing a new cloud-native application. To ensure security is integrated from the start, development teams are required to perform security testing at each stage of the development process. Which of the following security testing methods is BEST suited for identifying design flaws and vulnerabilities early in the SDLC, before coding is complete?
- APenetration testing
- BStatic Application Security Testing (SAST)
- CVulnerability scanning
- DDynamic Application Security Testing (DAST)
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
SAST analyzes source code, bytecode, or binary code for vulnerabilities without executing the application. This makes it ideal for identifying design flaws and coding errors early in the SDLC, even before the application is fully functional or deployed.
Why the other options are wrong
- A. Penetration testing is typically performed late in the SDLC on a running application.
- C. Vulnerability scanning typically targets deployed networks and systems, not source code during early development.
- D. DAST analyzes a running application, usually after development is largely complete.
Static Application Security Testing (SAST)
A white-box testing method that analyzes application source code, bytecode, or binary code without executing it to identify security vulnerabilities.
- Performed early in the SDLC (e.g., during coding).
- Identifies vulnerabilities in the code itself.
- Does not require a running application.
Memory trick: SAST for code, DAST for run, PenTest for the whole shebang.