ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During integration testing, a development team inserts an agent into its Java web application so that security findings are generated while the existing functional test suite exercises the code. Under ISC2 best practices, what principal advantage does this Interactive Application Security Testing (IAST) technique provide when compared with traditional Dynamic Application Security Testing (DAST)?
It avoids any integration with the build or runtime environment by scanning only external interfaces.
It eliminates the need for functional test traffic by automatically generating all inputs internally.
It pinpoints the specific file and line of code responsible for a vulnerability while the application is executing.
It can fully evaluate compiled binaries without running the application or providing test traffic.
IAST instruments the running application, so each time the functional tests trigger a vulnerability the agent can observe both the executed code path and the exact data involved. This allows the tool to report the precise file and line number that must be fixed. A network-only DAST scanner sees only HTTP requests and responses, so it can confirm that a flaw exists but cannot reliably identify where in the source the defect resides. IAST still needs test traffic, and it does not work on an application that is completely at rest, so claims that it requires no runtime integration or that it can scan binaries without execution are incorrect. Likewise, it does not generate its own test traffic; functional, unit, or synthetic tests must exercise the code.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between IAST and DAST?
Open an interactive chat with Bash
Why does IAST require functional test traffic to work?
Open an interactive chat with Bash
How does IAST pinpoint the exact file and line of code with vulnerabilities?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .