Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-97 Exam - Topic 7 Question 2 Discussion

(Debra Aniston has recently joined an MNC company as a DevSecOps engineer. Her organization develops various types of software products and web applications. The DevSecOps team leader provided an application code and asked Debra to detect and mitigate security issues. Debra used w3af tool and detected cross-site scripting and SQL injection vulnerability in the source code. Based on this information, which category of security testing tools is represented by w3af?.)
C) DAST.
A) IAST.
B) SCA.
D) SAST.

Eccouncil 312-97 Exam - Topic 7 Question 2 Discussion

Actual exam question for Eccouncil's 312-97 exam
Question #: 2
Topic #: 7
[All 312-97 Questions]

(Debra Aniston has recently joined an MNC company as a DevSecOps engineer. Her organization develops various types of software products and web applications. The DevSecOps team leader provided an application code and asked Debra to detect and mitigate security issues. Debra used w3af tool and detected cross-site scripting and SQL injection vulnerability in the source code. Based on this information, which category of security testing tools is represented by w3af?.)

Show Suggested Answer Hide Answer
Suggested Answer: C

w3af (Web Application Attack and Audit Framework) is a Dynamic Application Security Testing (DAST) tool. It analyzes running web applications by sending crafted requests and observing responses to identify vulnerabilities such as SQL injection, cross-site scripting, and authentication flaws. Unlike SAST tools, w3af does not require access to source code and instead operates externally, simulating real-world attack behavior. SCA focuses on third-party dependencies, and IAST requires runtime instrumentation within the application. Since Debra detected vulnerabilities by actively interacting with the application, w3af clearly represents DAST. DAST tools are especially valuable during the Build and Test stage, as they validate application behavior from an attacker's perspective before deployment.


Contribute your Thoughts:

0/2000 characters
Glendora
4 days ago
I feel confident about this. DAST fits perfectly here!
upvoted 0 times
...
Leonida
9 days ago
Yeah, w3af tests live apps for vulnerabilities.
upvoted 0 times
...
Richelle
14 days ago
Agreed! DAST is for dynamic testing, right?
upvoted 0 times
...
Janna
19 days ago
I think it's C) DAST. It scans running applications.
upvoted 0 times
...
Whitney
2 months ago
Definitely DAST, no doubt about it!
upvoted 0 times
...
Katie
2 months ago
Wait, are we sure it's not IAST?
upvoted 0 times
...
Rebeca
2 months ago
I thought w3af was more for SAST.
upvoted 0 times
...
Merri
3 months ago
Totally agree, it's for dynamic testing!
upvoted 0 times
...
Annamaria
3 months ago
w3af is a DAST tool, right?
upvoted 0 times
...
Carin
3 months ago
C) DAST. w3af is the perfect tool for Debra to use as a DevSecOps engineer to find those pesky vulnerabilities.
upvoted 0 times
...
Bettina
3 months ago
Haha, I bet Debra wishes she had a tool that could just magically fix those security issues for her!
upvoted 0 times
...
Celeste
3 months ago
C) DAST. w3af is a dynamic security testing tool, so it falls under the DAST category.
upvoted 0 times
...
Effie
4 months ago
C) DAST. Definitely DAST, as w3af is used to detect vulnerabilities in running web applications.
upvoted 0 times
...
Chan
4 months ago
C) DAST. w3af is a web application vulnerability scanner, which is a type of DAST (Dynamic Application Security Testing) tool.
upvoted 0 times
...
Felicitas
4 months ago
I’m confused about SAST and DAST sometimes. I guess w3af is DAST because it scans the application while it's running, right?
upvoted 0 times
...
Solange
4 months ago
I practiced a similar question, and I think w3af fits into the DAST category since it tests running applications.
upvoted 0 times
...
Jettie
5 months ago
I’m not entirely sure, but I remember something about IAST being more integrated with the code. Maybe it’s not that?
upvoted 0 times
...
Marlon
5 months ago
I think w3af is related to dynamic application security testing, so I would lean towards DAST.
upvoted 0 times
...
Amina
5 months ago
Alright, let me break this down. The question says Debra used the w3af tool to detect vulnerabilities, and that tool is a type of security testing tool. I'm going to go with C) DAST since that seems to fit the description.
upvoted 0 times
...
Gail
5 months ago
Wait, what's the difference between IAST, SCA, DAST, and SAST again? I'm a bit confused on the specifics of each type of security testing tool.
upvoted 0 times
...
Fredric
6 months ago
Okay, let me think this through. The question mentions that Debra used the w3af tool to detect vulnerabilities, so that's a clue. I'm going to go with C) DAST.
upvoted 0 times
...
Nettie
6 months ago
Ugh, I'm not too sure about this one. I know we covered security testing tools, but I'm having a hard time remembering the differences between them.
upvoted 0 times
...
Tegan
6 months ago
Hmm, this seems like a pretty straightforward question. I'm pretty confident I can figure this one out.
upvoted 0 times
...

Save Cancel