A web application team asks the vulnerability analyst to identify runtime input-validation and session-management flaws in a running portal. The analyst does not have source code access. Which scanning method should be implemented?
Select an answer to reveal the explanation.
Short Explanation
Think of it like smoke testing a running app: you poke the live login and input forms to see how they behave. If the flaw only shows up while the application is executing, you don't need the source—you need dynamic application scanning. Static or component reviews look at build-time artifacts, so they can miss runtime session handling.
Full Explanation
Dynamic application scanning exercises a running application by sending crafted requests to exposed interfaces and observing responses. It is appropriate when weaknesses such as improper input validation, broken authentication, or session-management flaws are expected to manifest during execution. The scanner evaluates behavior rather than source code, so it can reveal how authentication tokens, cookies, form fields, and API parameters react under real traffic. Static source code analysis scanning inspects code or build artifacts for patterns, but it cannot confirm whether a weakness is reachable in a deployed runtime or how session state behaves. Interactive application security testing relies on instrumentation inside the application or runtime environment, which is not available when only black-box scanning is required. Software composition analysis scanning identifies vulnerable dependencies and license issues in libraries, not flaws in application logic or session handling. Exam caveat: choose the method based on whether the evidence exists in code, dependencies, or live execution. Operational check: run authenticated and unauthenticated dynamic scans against staging endpoints and validate that session tokens and input validation failures are reproduced safely.