EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A security auditor is performing a black-box vulnerability assessment on a client's web application. The application uses a custom authentication mechanism. The auditor attempts to bypass authentication by manipulating session cookies and discovers that the application uses predictable session IDs based on user input and a weak seed. Which type of vulnerability analysis concept does this scenario primarily demonstrate?

  1. AInteractive Application Security Testing (IAST)
  2. BDynamic Application Security Testing (DAST)
  3. CStatic Application Security Testing (SAST)
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: B. Dynamic Application Security Testing (DAST)

Dynamic Application Security Testing (DAST) involves testing an application while it is running. The auditor is actively interacting with the live application, manipulating cookies, and observing its real-time behavior to find vulnerabilities, which aligns perfectly with DAST methodologies.

Why the other options are wrong

  • A. IAST combines elements of SAST and DAST, typically requiring instrumentation within the application.
  • C. SAST analyzes source code without executing the application.
  • D. SCA focuses on identifying vulnerabilities in open-source and third-party components.

Dynamic Application Security Testing (DAST)

A black-box testing method that analyzes an application in its running state to find vulnerabilities by simulating external attacks and observing the application's responses.

  • Tests the application from the outside, like an attacker.
  • Does not require access to source code.
  • Can find runtime configuration errors and environment-related issues.

Memory trick: To 'find flaws' in a 'running app', you need 'dynamic' interaction.

More System Hacking Phases and Attack Techniques questions