ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team is adding automated security checks to the CI/CD pipeline for a newly deployed RESTful microservice running in a containerized staging environment. The goal is to discover authentication weaknesses and injection issues by interacting with the live endpoints, without requiring access to source code or instrumentation inside the containers. Which testing approach best meets this requirement?
Perform a static code analysis scan of the microservice's source repository during the build
Run a dynamic application security test that attacks the running service through its exposed REST endpoints
Execute a software composition analysis to inventory and flag vulnerable open-source libraries in the container images
Attach instrumentation agents to the containers and execute interactive application security testing during unit tests
Because the team wants to probe the application in its running state through its external interfaces and does not have or need access to the source code, a dynamic application security test is most appropriate. DAST tools crawl and exercise live endpoints to detect problems such as SQL injection, cross-site scripting, and broken authentication. Static code analysis requires source code, instrumentation-based interactive testing must be embedded in the application, and software composition analysis focuses on library versions rather than runtime behavior.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is DAST and how does it test for security vulnerabilities?
Open an interactive chat with Bash
How does DAST differ from static code analysis?
Open an interactive chat with Bash
Why is software composition analysis not a sufficient solution in this case?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .