ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

A retail company is planning to implement a new point-of-sale (POS) system across all its stores. Management is concerned about potential vulnerabilities in the new system and wants to ensure that any security flaws are identified and remediated before go-live. Which of the following activities would be MOST effective for proactively identifying security weaknesses in the new POS system's code and configuration?

  1. ARegular log review and anomaly detection.
  2. BPenetration testing by an external red team.
  3. CDeployment of an Intrusion Prevention System (IPS).
  4. DStatic Application Security Testing (SAST).
Show answer & explanation

Correct answer: D. Static Application Security Testing (SAST).

Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities without actually executing the application. This makes it ideal for proactive identification of flaws during the development or pre-deployment phase.

Why the other options are wrong

  • A. Log review is a reactive measure, typically used during operations to detect ongoing issues, not proactive pre-deployment analysis of code.
  • B. Penetration testing is effective but typically performed on a running system, often later in the development cycle or just before deployment, and doesn't analyze the code directly in a static manner.
  • C. An IPS is a runtime protection mechanism for deployed systems, not a tool for proactively identifying code vulnerabilities before deployment.

Static Application Security Testing (SAST)

SAST is a white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application. It's typically performed early in the software development lifecycle.

  • Analyzes code without execution.
  • Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
  • Best used early in the SDLC for proactive security.

Memory trick: DAST for running, SAST for code.

More Security Operations questions