An organization relies heavily on a legacy application that processes sensitive customer data. Due to its age and complexity, standard vulnerability scanning tools often produce a high number of false positives or fail to adequately test its unique protocols. Furthermore, modifying the application's code is extremely risky and costly. The security team needs to determine if the application is vulnerable to real-world attacks. Which testing approach would be most appropriate given these constraints?
- AAutomated vulnerability scanning with default settings
- BSoftware Composition Analysis (SCA)
- CStatic Application Security Testing (SAST)
- DManual penetration testing focusing on business logic and custom protocols
Show answer & explanationAnswer & explanation
Correct answer: D. Manual penetration testing focusing on business logic and custom protocols
Given the 'legacy application', 'unique protocols', 'high false positives' from standard tools, and the need to test for 'real-world attacks' without 'modifying code', manual penetration testing is the most appropriate. It allows skilled testers to adapt to unique environments, understand complex business logic, and reduce false positives by manually verifying vulnerabilities, especially when automated tools struggle.
Why the other options are wrong
- A. Automated scanning is specifically stated to produce 'high false positives' and 'fail to adequately test unique protocols', making it unsuitable.
- B. SCA focuses on third-party components, not the custom code or unique protocols of a legacy application itself.
- C. SAST requires source code analysis, which is difficult/risky for legacy apps and doesn't address unique protocols or real-world exploitation.
Manual Penetration Testing
A hands-on, human-driven security test where skilled testers simulate real-world attacks to identify and exploit vulnerabilities that automated tools might miss, particularly in complex or unique environments.
- Human intelligence and adaptability
- Effective for complex business logic and custom applications
- Reduces false positives compared to automated tools
Memory trick: Old apps need human touch, not just robots.