nerdexam
(ISC)2

CCSP · Question #746

Different security testing methodologies offer different strategies and approaches to testing systems, requiring security personnel to determine the best type to use for their specific…

The correct answer is B. Knowledge of the system. Dynamic application security testing (DAST) is considered "black-box" testing and begins with no inside knowledge of the application or its configurations. Everything about it must be discovered during its testing. As with most types of testing, dynamic application security…

Submitted by cyberguy42· Apr 18, 2026Cloud Application Security

Question

Different security testing methodologies offer different strategies and approaches to testing systems, requiring security personnel to determine the best type to use for their specific circumstances. What does dynamic application security testing (DAST) NOT entail that SAST does?

Options

  • ADiscovery
  • BKnowledge of the system
  • CScanning
  • DProbing

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    93% (26)
  • C
    4% (1)

Explanation

Dynamic application security testing (DAST) is considered "black-box" testing and begins with no inside knowledge of the application or its configurations. Everything about it must be discovered during its testing. As with most types of testing, dynamic application security testing (DAST) involves probing, scanning, and a discovery process for system information.

Topics

#DAST#SAST#Application Security Testing#Vulnerability Scanning

Community Discussion

No community discussion yet for this question.

Full CCSP Practice