ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium
A security manager is evaluating various vulnerability assessment tools. They are particularly interested in a tool that can identify common coding errors, potential buffer overflows, and SQL injection flaws by analyzing the application's source code without executing it. Which type of tool is the manager seeking?
- ASoftware Composition Analysis (SCA)
- BStatic Application Security Testing (SAST)
- CDynamic Application Security Testing (DAST)
- DInteractive Application Security Testing (IAST)
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) tools analyze an application's source code, bytecode, or binary code without executing it to find security vulnerabilities. This directly matches the requirement of analyzing source code without execution for coding errors like buffer overflows and SQL injection.
Why the other options are wrong
- A. SCA identifies vulnerabilities in open-source and third-party components, not custom source code analysis for coding errors.
- C. DAST tests applications in their running state, interacting with the application as a user would.
- D. IAST combines elements of SAST and DAST, testing applications in a running state while analyzing code.
SAST (Static Application Security Testing)
A security testing method that analyzes an application's source code, bytecode, or binary code for vulnerabilities without actually executing the application.
- Analyzes code without execution (static)
- Identifies vulnerabilities early in SDLC
- Good for finding coding errors like buffer overflows, SQL injection
Memory trick: App tests: SAST for code, DAST for running, IAST for both.