Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planEasy
A global enterprise is adopting Azure DevOps for its software development lifecycle. They have a strict security policy requiring that all code changes must undergo an automatic security scan for common vulnerabilities before merging into the main branch. This scan must identify issues like SQL injection, cross-site scripting (XSS), and insecure API endpoints. Which type of security testing should be integrated into their Azure DevOps pipeline to meet this requirement?
- AInteractive Application Security Testing (IAST)
- BStatic Application Security Testing (SAST)
- CDynamic Application Security Testing (DAST)
- DSoftware Composition Analysis (SCA)
Show answer & explanationAnswer & explanation
Correct answer: B. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes application source code, bytecode, or binary code for security vulnerabilities without actually executing the application. It is ideal for integration into CI/CD pipelines to identify issues like SQL injection and XSS before code is merged.
Why the other options are wrong
- A. IAST combines elements of SAST and DAST, running within the application during execution. While powerful, SAST is the primary method for pre-merge code analysis.
- C. DAST tests applications in their running state, typically after deployment, and would not meet the 'before merging' requirement.
- D. SCA focuses on identifying vulnerabilities in open-source and third-party components, not directly in the custom-written code for SQL injection or XSS.
Static Application Security Testing (SAST)
A white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
- Does not require a running application.
Memory trick: Code security: Scan early, scan often, scan for everything!