StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 8: Software development security

Application security testing: SAST, DAST, SCA, IAST

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Application security testing tools automate the search for vulnerabilities in software. The exam expects you to know the four main categories, how each works, where it fits in the development lifecycle, and its strengths and blind spots. Mature programs use several together because each sees a different slice of the problem: your own code at rest, your application in motion, and the third-party components you did not write.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan