Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A software development company wants to ensure that all code developed internally is free from known vulnerabilities before it is deployed. They need a tool that can analyze the source code and identify security flaws early in the development lifecycle. Which type of tool would be most appropriate?

  1. ARuntime Application Self-Protection (RASP)
  2. BDynamic Application Security Testing (DAST)
  3. CStatic Application Security Testing (SAST)
  4. DNetwork Intrusion Detection System (NIDS)
Show answer & explanation

Correct answer: C. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) tools analyze application source code, bytecode, or binary code for security vulnerabilities without actually executing the program. This allows for early detection of flaws in the development lifecycle.

Why the other options are wrong

  • A. RASP protects applications during runtime, after deployment, not during development.
  • B. DAST tests applications during runtime by executing them, which is later in the cycle than 'early in development'.
  • D. NIDS monitors network traffic for intrusions and is not an application security testing tool.

Static Application Security Testing (SAST)

A white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Performed early in the SDLC (Shift Left).
  • Identifies vulnerabilities in the code itself.
  • Does not require a running application.

Memory trick: SAST is like a 'code editor with security glasses' for early flaw detection.

More Endpoint Security questions