Study. uk . com
  1. Home
  2. All questions
  3. Question 227

CompTIA Security+ study material · question 227 of 611

Which testing approach reads source code without executing it?

  1. Static analysis
  2. Dynamic analysis
  3. Penetration testing
  4. Fuzzing
Show the answer

Answer: A. Static analysis

Static analysis finds patterns early in the lifecycle; dynamic analysis exercises the running application instead.

Source: NIST SP 800-115 (NIST) — SP 800-115 § 3 Review Techniques

Challenge yourself on this topic → Study as cards