A security analyst is reviewing the source code of an application in order to identify misconfigurations and vulnerabilities. Which of the following kinds of analysis best describes this review?
Choose an answer
Tap an option to check your answer.
Correct answer: Static.
Why this is the answer
Static analysis, also known as Static Application Security Testing (SAST), involves examining an application's source code, bytecode, or binary code without actually executing the program. This method helps identify potential vulnerabilities, coding errors, and misconfigurations early in the development lifecycle. The security analyst is directly reviewing the code, which is the hallmark of static analysis. Dynamic analysis (DAST) involves executing the application and observing its behavior to find vulnerabilities, often by simulating attacks. Gap analysis compares the current state of security with a desired state to identify missing controls or processes. Impact analysis assesses the potential consequences of a security incident or change. These options do not accurately describe the act of reviewing source code directly.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed