SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy
A software company is developing a new mobile application that will handle sensitive customer data. Before deployment, the application must undergo a thorough security review. The development team wants to identify vulnerabilities in the application's source code without actually executing the code. Which type of security testing would be most appropriate for this requirement?
- APenetration Testing
- BDynamic Application Security Testing (DAST)
- CStatic Application Security Testing (SAST)
- DInteractive Application Security Testing (IAST)
Show answer & explanationAnswer & explanation
Correct answer: C. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code without executing it, making it ideal for identifying vulnerabilities early in the development lifecycle.
Why the other options are wrong
- A. Penetration testing is a manual or automated simulation of an attack on a running system, also not matching the 'without executing' requirement.
- B. DAST tests a running application by attacking it from the outside, which is not what's described (without executing the code).
- D. IAST combines elements of SAST and DAST, requiring the application to be running in a test environment, which is contrary to the 'without executing' requirement.
Static Application Security Testing (SAST)
A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
- Does not require a running application.
Memory trick: Test the app: static code, dynamic run, or interactive fun.