SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A software development team is adopting a DevSecOps methodology. They want to integrate security checks early and continuously throughout their development pipeline. Which of the following practices is most effective for finding security vulnerabilities within the application's source code before deployment?
- AImplementing Dynamic Application Security Testing (DAST) in the production environment.
- BUtilizing Static Application Security Testing (SAST) during the build phase.
- CConducting manual code reviews after the application is released to users.
- DPerforming regular penetration testing against the deployed application.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilizing Static Application Security Testing (SAST) during the build phase.
SAST tools analyze source code for vulnerabilities without executing the application, making them ideal for integration into the build phase of a DevSecOps pipeline. This allows developers to find and fix issues early, before deployment.
Why the other options are wrong
- A. DAST tests a running application, typically later in the cycle, and doesn't analyze source code directly.
- C. Manual code reviews after release are too late in the cycle and not continuous, contradicting DevSecOps principles.
- D. Penetration testing is a post-deployment activity and doesn't analyze source code directly during the build phase.
Static Application Security Testing (SAST)
A white-box testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (e.g., during development or build).
- Identifies vulnerabilities in the code itself.
- Does not require a running application.
Memory trick: App security tests are like checking a car: some look at the blueprints, others test it on the road.