ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityEasy
A software development team is employing a technique to automatically discover potential vulnerabilities by feeding malformed or unexpected inputs to an application. This process is being conducted during the testing phase. What is this technique called?
- AFuzzing
- BSoftware Composition Analysis (SCA)
- CDynamic Application Security Testing (DAST)
- DStatic Application Security Testing (SAST)
Show answer & explanationAnswer & explanation
Correct answer: A. Fuzzing
Fuzzing (or fuzz testing) is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program. The program is then monitored for exceptions such as crashes, assertions, or potential memory leaks, which can indicate security vulnerabilities.
Why the other options are wrong
- B. SCA identifies third-party components and their known vulnerabilities, not by feeding inputs to the application.
- C. DAST tests a running application but typically uses more structured attacks; fuzzing specifically focuses on malformed/random inputs.
- D. SAST analyzes source code without execution; fuzzing requires execution with varied inputs.
Fuzzing
An automated software testing technique that involves injecting malformed, unexpected, or random data into a program's inputs to discover software defects and security vulnerabilities.
- Tests application robustness to bad input
- Can uncover buffer overflows, crashes, memory leaks
- Effective for parsing engines, network protocols
Memory trick: Fuzzing's the game, bad data's its aim, finding crashes before they proclaim.