exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 384 discussion

Actual exam question from ISC's CCSP
Question #: 384
Topic #: 1
[All CCSP Questions]

What does static application security testing (SAST) offer as a tool to the testers that makes it unique compared to other common security testing methodologies?

  • A. Live testing
  • B. Source code access
  • C. Production system scanning
  • D. Injection attempts
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Static application security testing (SAST) is conducted against offline systems with previous knowledge of them, including their source code. Live testing is not part of static testing but rather is associated with dynamic testing. Production system scanning is not appropriate because static testing is done against offline systems.
Injection attempts are done with many different types of testing and are not unique to one particular type. It is therefore not the best answer to the question.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
akg001
5 months ago
Selected Answer: B
B. Source code access
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago