SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

A security team is conducting a comprehensive assessment of their web application. They use an automated tool to scan the application's code for known vulnerabilities and coding errors without executing the code. This process is integrated into their Continuous Integration/Continuous Deployment (CI/CD) pipeline to identify issues early in the development lifecycle. What type of security assessment is being performed?

  1. AInteractive Application Security Testing (IAST)
  2. BDynamic Application Security Testing (DAST)
  3. CStatic Application Security Testing (SAST)
  4. DRuntime Application Self-Protection (RASP)
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) involves analyzing an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application. This matches the description of scanning code for vulnerabilities 'without executing the code' and being integrated into the CI/CD pipeline.

Why the other options are wrong

  • A. IAST combines elements of SAST and DAST, requiring the application to be running to monitor its behavior.
  • B. DAST tests applications in their running state, which is contrary to 'without executing the code'.
  • D. RASP is a security technology that protects applications by monitoring their execution in real-time, not a testing methodology.

Static Application Security Testing (SAST)

A white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.

  • Performed early in the SDLC (Shift Left).
  • Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
  • Does not require a running application.

Memory trick: SAST is Static, DAST is Dynamic, IAST is Interactive.

More Risk Identification, Monitoring, and Analysis questions