Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A financial services company is developing an application that processes credit card information. They are required by PCI DSS compliance to regularly scan their application code for security vulnerabilities. Which type of tool should be integrated into their CI/CD pipeline to automatically identify security flaws in the source code before deployment?

  1. ASoftware Composition Analysis (SCA)
  2. BStatic Application Security Testing (SAST)
  3. CInteractive Application Security Testing (IAST)
  4. DDynamic Application Security Testing (DAST)
Show answer & explanation

Correct answer: B. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) tools analyze application source code, bytecode, or binary code for security vulnerabilities without executing the application. This is ideal for integration into a CI/CD pipeline to catch flaws early in the development cycle, directly addressing the requirement to scan code for vulnerabilities.

Why the other options are wrong

  • A. SCA tools identify known vulnerabilities in open-source and third-party components, which is important but distinct from scanning the custom application's own source code for flaws.
  • C. IAST tools combine elements of SAST and DAST, running within the application during testing, but SAST is the primary method for 'scanning application code' pre-execution.
  • D. DAST tools test applications in their running state, typically after deployment, not directly on the source code in the pipeline.

Static Application Security Testing (SAST)

A white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.

  • Performed early in the SDLC (Shift Left).
  • Identifies vulnerabilities in custom code.
  • Integrated into CI/CD pipelines.

Memory trick: To 'Spot Code Flaws Early', SAST is the key.

More Develop a security and compliance plan questions