exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 220 discussion

Actual exam question from CompTIA's CS0-002
Question #: 220
Topic #: 1
[All CS0-002 Questions]

In web application scanning, static analysis refers to scanning:

  • A. the system for vulnerabilities before installing the application
  • B. the compiled code of the application to detect possible issues.
  • C. an application that is installed and active on a system.
  • D. an application that is installed on a system that is assigned a static IP.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
2Fish
Highly Voted 2 years, 1 month ago
Selected Answer: B
B. From my research, Static analysis can be run on compiled code.
upvoted 5 times
...
Brian93
Most Recent 2 years, 1 month ago
Selected Answer: B
B is the answer
upvoted 1 times
...
brollo
2 years, 1 month ago
Another very dumb question: A. honestly I don't like this answer because it's too general and testing before installation doesn't really explain it carefully. B. static code analysis means the "Process of reviewing uncompiled source code either manually or using automated tools". B is saying compiled code so it can't be static code analysis. In the end, I think I'm gonna go with A but again a very poor question
upvoted 2 times
supernewtechnewbie
1 year, 8 months ago
We get it the questions don't make sense. How does that help the community learn better?
upvoted 1 times
...
...
CatoFong
2 years, 2 months ago
Selected Answer: B
B. is correct
upvoted 1 times
...
david124
2 years, 2 months ago
Selected Answer: B
B ez pz
upvoted 1 times
...
Merc16
2 years, 2 months ago
Selected Answer: B
I think B should read - the completed code of the application to detect possible issues. see the word complete instead of compiled.
upvoted 1 times
...
trojan123
2 years, 3 months ago
Selected Answer: A
Static code analysis is typically performed on the source code of an application before it is compiled. The process involves analyzing the source code for potential vulnerabilities or issues without executing it. This allows for the identification of issues early on in the development process, before the application is compiled and deployed. Performing static code analysis on the compiled code can also be done but typically is less effective as it is harder to analyze the code as it loses some of its original structure and also the scanner won't be able to see the potential vulnerabilities that might have been introduced by the developers during the coding process. It is important to note that static code analysis is just one step in the software development life cycle (SDLC) and should be integrated with other security testing methodologies like dynamic analysis, penetration testing, and vulnerability scanning to provide comprehensive security testing of an application.
upvoted 2 times
trojan123
2 years, 3 months ago
Very bad answers used here: A. the system for vulnerabilities before installing the application. - not the system scanning, but code of app itself, does they name the system the app itself? B. the compiled code of the application to detect possible issues. - it should be done before code is compiled. We need just to guess here. I am going with A. Not sure
upvoted 1 times
...
...
Frog_Man
2 years, 4 months ago
Static analysis is done before the code is compiled - by definition.
upvoted 2 times
...
bob12356
2 years, 4 months ago
Selected Answer: B
This type of analysis is performed before the application is installed and active on a system, and it involves examining the code without actually executing it in order to identify potential vulnerabilities or security risks.
upvoted 2 times
...
sho123
2 years, 4 months ago
Selected Answer: B
the answer is B , the already said in web application not a system
upvoted 1 times
...
marc4354345
2 years, 4 months ago
Selected Answer: A
Static code analysis examines the source code of an application. That must happen before compilation or deployment. Definitely A.
upvoted 3 times
...
mrodmv
2 years, 4 months ago
Selected Answer: B
B makes sense
upvoted 1 times
...
prntscrn23
2 years, 4 months ago
Selected Answer: B
As per CYSA+ 002 Study Guide: Static analysis is conducted by reviewing the code for an application. Static analysis does not run the program; instead, it focuses on understanding how the program is written and what the code is intended to do.
upvoted 2 times
...
iking
2 years, 4 months ago
Selected Answer: A
A. the system for vulnerabilities before installing the application. Static means before running/installing an app
upvoted 2 times
bob12356
2 years, 4 months ago
Technically yes, but the best answer here is B because we are defining static code analysis, not the implications of static code analysis
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago