6A: Scan Identified Targets Flashcards
2.4 Given a scenario, perform vulnerability scanning. 5.3 Explain use cases of the following tools during the phases of a penetration test.
1
Q
Testing that is done early in the software development life cycle to examine the code for security vulnerabilities.
A
Static Application Security Testing (SAST)
2
Q
Testing that is done after code is placed into production and is able to unearth vulnerabilities that are evident once the code is in production.
A
Dynamic Application Security Testing (DAST)
3
Q
A NIST framework that outlines various accepted practices for automating vulnerability scanning. A US standard used to ensure applications are in-line with mandated security requirements.
A
Security Content Automation Protocol (SCAP)