ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityEasy

A software development team is employing a technique to automatically discover potential vulnerabilities by feeding malformed or unexpected inputs to an application. This process is being conducted during the testing phase. What is this technique called?

  1. AFuzzing
  2. BSoftware Composition Analysis (SCA)
  3. CDynamic Application Security Testing (DAST)
  4. DStatic Application Security Testing (SAST)
Show answer & explanation

Correct answer: A. Fuzzing

Fuzzing (or fuzz testing) is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program. The program is then monitored for exceptions such as crashes, assertions, or potential memory leaks, which can indicate security vulnerabilities.

Why the other options are wrong

  • B. SCA identifies third-party components and their known vulnerabilities, not by feeding inputs to the application.
  • C. DAST tests a running application but typically uses more structured attacks; fuzzing specifically focuses on malformed/random inputs.
  • D. SAST analyzes source code without execution; fuzzing requires execution with varied inputs.

Fuzzing

An automated software testing technique that involves injecting malformed, unexpected, or random data into a program's inputs to discover software defects and security vulnerabilities.

  • Tests application robustness to bad input
  • Can uncover buffer overflows, crashes, memory leaks
  • Effective for parsing engines, network protocols

Memory trick: Fuzzing's the game, bad data's its aim, finding crashes before they proclaim.

More Software Development Security questions