SecurityQA/Testing
SAST / DAST
Also written as Static Application Security Testing, Dynamic Application Security Testing
Two ways of finding security flaws: SAST reads the source code looking for dangerous patterns; DAST attacks the running application from the outside.
Think of it like
SAST is reading a building's blueprints for fire-safety violations. DAST is walking in and trying the doors.
Junior or senior?
Junior sounds like
Names the tools in the pipeline.
Senior sounds like
Talks about false positives and triage — the reason most SAST rollouts get ignored within a quarter.
Ask them
“How did your team handle the false positives from your security scanner?”