SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard

A financial institution is developing a new mobile banking application. The project manager is concerned about potential risks from third-party libraries and open-source components used in the application. To proactively identify and mitigate these risks during the development lifecycle, which security assessment technique should be continuously integrated?

  1. AExternal penetration testing
  2. BUser Acceptance Testing (UAT)
  3. CStatic Application Security Testing (SAST)
  4. DDynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the code. It is ideal for identifying vulnerabilities in third-party libraries and open-source components early in the development lifecycle, allowing developers to fix issues before deployment. DAST tests running applications, UAT is for user functionality, and external penetration testing is typically performed late in the cycle on a deployed application.

Why the other options are wrong

  • A. External penetration testing is performed on a running application, typically at later stages, and is less effective for proactively finding issues in source code/libraries during development.
  • B. UAT focuses on functional requirements from a user perspective, not security vulnerabilities in code.
  • D. DAST tests a running application and is less effective at directly identifying vulnerabilities within the static code of third-party libraries before runtime.

Static Application Security Testing (SAST)

A white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Performed early in the SDLC (Shift Left).
  • Identifies vulnerabilities like SQL injection, buffer overflows, cross-site scripting.
  • Effective for finding issues in third-party components and open-source code.

Memory trick: SAST for code, DAST for runtime, IAST for both, Pen Test for real attacks.

More Risk Identification, Monitoring, and Analysis questions