ExamGecko
Home Home / ISC / CCSP
Question list
Search
Search

Question 384 - CCSP discussion

Report
Export

What does static application security testing (SAST) offer as a tool to the testers that makes it unique compared to other common security testing methodologies?

A.
Live testing
Answers
A.
Live testing
B.
Source code access
Answers
B.
Source code access
C.
Production system scanning
Answers
C.
Production system scanning
D.
Injection attempts
Answers
D.
Injection attempts
Suggested answer: B

Explanation:

Static application security testing (SAST) is conducted against offline systems with previous knowledge of them, including their source code. Live testing is not part of static testing but rather is associated with dynamic testing. Production system scanning is not appropriate because static testing is done against offline systems. Injection attempts are done with many different types of testing and are not unique to one particular type. It is therefore not the best answer to the question.

asked 18/09/2024
claudine Nguepnang
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first