A developer asks your vulnerability team to review a new web application before it is deployed. The application is not running yet, but the team wants to catch insecure coding patterns such as unsafe input handling and hardcoded secrets. Which vulnerability scanning method is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Think of it like reading the blueprint before the house is built: you inspect the code, not the running building. Static analysis finds insecure patterns before execution, while dynamic methods wait until the app is live. Don't confuse pre-deployment code review with testing a live application.
Full Explanation
Static application security testing analyzes source code or infrastructure-as-code templates without launching the application. It parses syntax and control flow to identify dangerous patterns such as SQL injection sinks, unsafe deserialization, weak cryptographic practices, or hardcoded secrets. Because the goal is pre-deployment code-level weakness discovery, SAST is the correct method. Dynamic application security testing is not appropriate because it sends crafted requests to a running application and observes responses, so it cannot inspect code that is not executable. Software composition analysis is not appropriate because it inventories open-source and third-party components and compares them against vulnerability databases, rather than analyzing the organization's own code. Interactive application security testing is not appropriate because it relies on runtime instrumentation and agent-based observation while the application executes, which defeats the requirement to avoid executing the application. Exam caveat: CompTIA expects you to match the scanning method to the artifact being tested—source code, running application, dependencies, or infrastructure—not to a preferred product. Operational check: Confirm the scanner can ingest the repository branch under review, suppress known false positives, and produce developer-actionable findings before the release gate.