exam questions

Exam CCSK All Questions

View all questions & answers for the CCSK exam

Exam CCSK topic 1 question 143 discussion

Actual exam question from CSA's CCSK
Question #: 143
Topic #: 1
[All CCSK Questions]

Which type of application security testing should incorporate checks on API calls to the cloud service?

  • A. Dynamic Application Security Testing (DAST)
  • B. Unit Testing
  • C. Functional Testing
  • D. Static Application Security Testing (SAST)
  • E. All of the above
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
c0d2291
3 weeks ago
Selected Answer: E
SAST itself does not provide enough coverage IMHO
upvoted 1 times
...
romaso82
4 months, 1 week ago
THe answer is "A"
upvoted 1 times
...
JAMBER
1 year ago
Selected Answer: D
Pg 113: Static Application Security Testing (SAST): On top of the normal range of tests, these should ideally incorporate checks on API calls to the cloud service. They should also look for any static embedded credentials for those API calls, which is a growing problem.
upvoted 3 times
...
CloudSecurityMan
1 year, 3 months ago
Selected Answer: D
Static Application Security Testing (SAST) is On top of the normal range of tests, these should ideally incorporate checks on API calls to the cloud service. Hence, Correct answer is D.
upvoted 2 times
...
byfener
1 year, 4 months ago
A. Dynamic Application Security Testing (DAST) Dynamic Application Security Testing (DAST) is a type of application security testing that involves testing the application in its running state by sending various inputs and analyzing the responses. When it comes to checking API calls to the cloud service, DAST is particularly relevant. It simulates how an attacker might interact with an application and its APIs by making requests and evaluating the responses for vulnerabilities. Unit Testing (B), Functional Testing (C), and Static Application Security Testing (SAST) (D) are not specifically focused on testing API calls to cloud services, although they play important roles in broader application security practices. Option E ("All of the above") is not accurate in this context as DAST is the most relevant choice for checking API calls to cloud services among the options given.
upvoted 1 times
...
moota
1 year, 9 months ago
Selected Answer: D
10.1.3 Static Application Security Testing (SAST): On top of the normal range of tests, these should ideally incorporate checks on API calls to the cloud service. They should also look for any static embedded credentials for those API calls, which is a growing problem.
upvoted 3 times
...
LauriRo
1 year, 10 months ago
Static Application Security Testing (SAST): On top of the normal range of tests, these should ideally incorporate checks on API calls to the cloud service.
upvoted 2 times
...
A_Nevermind
2 years, 1 month ago
Selected Answer: E
API calls should be tested with all the methods reported
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago