exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 36 discussion

Actual exam question from CompTIA's CS0-002
Question #: 36
Topic #: 1
[All CS0-002 Questions]

A software development team asked a security analyst to review some code for security vulnerabilities. Which of the following would BEST assist the security analyst while performing this task?

  • A. Static analysis
  • B. Dynamic analysis
  • C. Regression testing
  • D. User acceptance testing
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Charlieb123
Highly Voted 3 years, 3 months ago
Selected Answer: A
Agreed it's A. What is static analysis in cyber security? Image result for static analysis cyber security Static application security testing (SAST), or static analysis, is a testing methodology that analyzes source code to find security vulnerabilities that make your organization's applications susceptible to attack. Regression testing is a software testing practice that ensures an application still functions as expected after any code changes, updates, or improvements. Which would fall into the Security Analyst remit.
upvoted 9 times
2Fish
2 years, 1 month ago
Agree.. this is Static Analysis.
upvoted 1 times
...
...
awad1997
Highly Voted 3 years, 3 months ago
Selected Answer: A
Clearly its A
upvoted 5 times
...
iraidesc
Most Recent 2 years, 5 months ago
Selected Answer: A
Process of reviewing uncompiled source code either manually or using automated tools -Automated tools can reveal issues ranging from faulty logic to insecure libraries before the app even runs ▪ Code Review ● The process of peer review of uncompiled source code by other developers
upvoted 1 times
...
MrRobotJ
2 years, 5 months ago
Why not B?
upvoted 2 times
...
okioki
2 years, 5 months ago
Selected Answer: C
Answer from the Course Class
upvoted 1 times
...
gwanedm
2 years, 7 months ago
the answer is A A regression test evaluates whether changes in software have caused previously existing functionality to fail
upvoted 1 times
...
R00ted
2 years, 7 months ago
Selected Answer: A
"Unlike many other methods, static analysis does not run the program; instead, it focuses on understanding how the program is written and what the code is intended to do. Static code analysis can be conducted using automated tools or manually by reviewing the code—a process sometimes called “code understanding.” Automated static code analysis can be very effective at finding known issues, and manual static code analysis helps identify programmer-induced errors." Comptia CYSA Dtudy Guide
upvoted 3 times
...
Fastytop
2 years, 7 months ago
Selected Answer: C
Regression testing.
upvoted 2 times
cyberseckid
2 years, 7 months ago
definitely not , please read regression testing definition first.
upvoted 2 times
IT_Master_Tech
2 years, 5 months ago
https://www.guru99.com/regression-testing.html
upvoted 1 times
...
...
...
EVE12
2 years, 8 months ago
Static analysis refers to testing or examining software when it is not running. The most common type of static analysis is code review. Code review is the systematic investigation of the code for security and functional problems. It can take many forms, from simple peer review to formal code review. Code review was covered earlier in this chapter. More on static analysis was covered in Chapter 4.
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: A
looks good to me
upvoted 1 times
...
FrancisBakon
2 years, 9 months ago
People who are confused why it is not Dynamic (B) or Regression (C) the keyword here is 'code'. You perform dynamic or regression testing while running the program.
upvoted 3 times
...
FrancisBakon
2 years, 9 months ago
Selected Answer: A
It is not regression testing. Because that is not job of Analyst. Regression testing is in general of QA/Test team. Analyst usually performs either perform static (code scanning) or Dynamic (VA/fuzzing)
upvoted 1 times
...
Threat_Analyst
2 years, 11 months ago
A security analyst reviewing code should be done with a Dynamic analysis tool as coding is not a usual strength of security analysts just scripting.
upvoted 2 times
...
f3lix
2 years, 12 months ago
This is indeed a very tricky one. Statistic analysis - code analysis (not software analysis) Regression Testing - Software Test to ensure it functions as it should. Questions asks about examining code and not software, I think here I'll be going with A.
upvoted 1 times
...
encxorblood
3 years ago
C - Regression testing is testing existing software applications to make sure that a change or addition hasn't broken any existing functionality.
upvoted 1 times
...
RoPsur
3 years, 1 month ago
Selected Answer: C
Regression testing is making sure past vulnerabilities are not resurfaced when implementing new code. We are not software developers to pick A...
upvoted 2 times
...
wazowski1321
3 years, 1 month ago
Selected Answer: A
A. static analysis
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago