ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium
A security team is conducting a vulnerability assessment on a new web application. They are using an automated tool that scans the application's code for known weaknesses and common misconfigurations before it is deployed to production. Which type of assessment is being performed?
- ADynamic Application Security Testing (DAST)
- BStatic Application Security Testing (SAST)
- CSoftware Composition Analysis (SCA)
- DInteractive Application Security Testing (IAST)
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
The scenario describes an automated tool scanning application code for weaknesses prior to deployment, which is the definition of Static Application Security Testing (SAST). DAST tests a running application, IAST combines static and dynamic analysis, and SCA focuses on open-source component vulnerabilities.
Why the other options are wrong
- A. DAST tests a running application by attacking it from the outside.
- C. SCA identifies vulnerabilities in third-party and open-source components.
- D. IAST combines elements of both SAST and DAST, analyzing code during runtime.
Static Application Security Testing (SAST)
SAST is a white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Performed early in the Software Development Life Cycle (SDLC) – 'shift-left'.
- Identifies vulnerabilities like SQL injection, cross-site scripting (XSS), and buffer overflows.
- Does not require a running application, making it suitable for developers.
Memory trick: SAST is 'Static' because it scans code at rest, DAST is 'Dynamic' because it attacks a running app.