ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During security testing of a containerized Java microservice deployed to a test Kubernetes cluster, the QA team already runs an extensive automated API regression suite in the CI/CD pipeline. The cloud security engineer wants to detect both code-level flaws and runtime vulnerabilities as the tests execute, receiving immediate feedback mapped to the exact lines of code and with minimal false positives. Which security testing technique best meets these requirements?
Interactive application security testing (IAST) works by instrumenting the running application-often through agents or sensors embedded in the runtime-so that, while normal functional tests or automated API calls execute, the tool can observe data flows, configuration, and control paths from inside the application. This dual visibility lets it combine the strengths of static analysis (code insight) and dynamic testing (runtime context), producing detailed, line-of-code findings with relatively low false-positive rates.
Static application security testing (SAST) analyzes source or bytecode without executing the program, so it lacks runtime context. Dynamic application security testing (DAST) probes a running application externally through HTTP requests, giving runtime visibility but no direct code correlation. Software composition analysis (SCA) inventories third-party components to flag vulnerable libraries and licenses but does not analyze custom code paths during execution. Therefore, IAST is the most suitable choice for the scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between SAST and IAST?
Open an interactive chat with Bash
How does IAST achieve low false-positive rates?
Open an interactive chat with Bash
Why doesn’t DAST fulfill the requirements in this scenario?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .