SAST vs. DAST vs. SCA

How to tell them apart on a resume

SAST (code scanning)

SonarQube, Checkmarx, Semgrep, Fortify, Veracode, CodeQL, secure code review — run in the build pipeline.

DAST (running-app testing)

Burp Suite, OWASP ZAP, Acunetix, scanning staging environments, web application security testing — close to penetration testing.

SCA (dependency scanning)

Snyk, Dependabot, Black Duck, Mend, SBOMs, CVE triage, licence compliance — managing third-party and open-source risk.

The question that settles it

“Which kind of scanning did you set up — your own code, the running app, or third-party libraries — and how did you stop developers ignoring the results?”

Read the full definitions

Open the full tool for the other look-alike pairs, role profiles, and the JD decoder.