Static Application Security Testing

Final Quiz

Connecting to LMS... Progress: in progress

Assessment

1. What is Static Application Security Testing?
2. How does SAST differ from DAST?
3. Why is SAST useful in the Secure SDLC?
4. What is a source in static analysis?
5. What is a sink in static analysis?
6. What is taint tracking at a high level?
7. What is a SAST finding?
8. What is a false positive?
9. What is a false negative?
10. Why does finding severity need context?
11. What should good remediation guidance include?
12. Why can suppressing findings be risky?
13. What is a baseline scan useful for?
14. Why should SAST be integrated into CI/CD carefully?
15. Which metric is useful for SAST program health?
16. Which statement best summarizes SAST?