Q10Software Development and DesignMultiple answers
Which two statements outline advantages of static code analysis compared with unit tests? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 12
20
It's A and B.
"Taint sources are locations in the program where data is being read from a potentially risky source, and include things like environment variables, data, files, file metadata"
This is something we review during static code analysis along with proper coding style and standards.
8
Are A and B the right answers?
C may be wrong.
4
will go with A and B based on:
https://owasp.org/www-community/controls/Static_Code_Analysis
A, B 4
Selected Answer: AB
Static code analysis complements dynamic testing to provide extra advantages:
- Error detection: Static code analysis can identify hundreds of classes of bugs related to concurrency, tainted data, data flow, and static and dynamic memory. Some bugs are almost impossible to detect with the dynamic testing.
- Security vulnerabilities detection: Static code analysis can detect common vulnerabilities, such as those identified by OWASP, in the code and imported libraries.
- Low cost: Static code analysis may be easily automated without the overhead of writing test cases, instrumenting the code, and program execution.
- Coding standards compliance: Static analysis tools can analyze source syntax and enforce coding standards.
- Better source code: Static code analysis tools can identify the unused code.
Source: Cisco DEVCOR 350-901 Study Guide
A, B 3
Selected Answer: AB
A and B are correct.
Static code analysis complements dynamic testing to provide extra advantages:
- Error detection: Static code analysis can identify hundreds of classes of bugs related to concurrency, tainted data, data flow, and static and dynamic memory. Some bugs are almost impossible to detect with dynamic testing.
- Security vulnerabilities detection: Static code analysis can detect common vulnerabilities, such as those identified by OWASP, in the code and imported libraries.
- Low cost: Static code analysis may be easily automated without the overhead of writing test cases, instrumenting the code, and program execution.
- Coding standards compliance: Static analysis tools can analyze source syntax and enforce coding standards.
- Better source code: Static code analysis tools can identify unused code.
2
The answers are B and D
2
I would go for A and B, as D sounds like it is too much related to the running code.
A, B 2
Selected Answer: AB
I agree with Bloody_sausage and B3nd3cida.
A, B 2
Selected Answer: AB
Correct answer: A & B
1
A and D
1
For me B is one of the answers but though choice between A and D.
Tainted data where input is not checked is not being tested by unit testing and therefore is a benefit of SCA. On the other hand, race conditions are also possible to check on SCA.
1
it's very hard to determine race conditions by just looking at the code