SecurityQA/Testing

SAST / DAST

Also written as Static Application Security Testing, Dynamic Application Security Testing

Two ways of finding security flaws: SAST reads the source code looking for dangerous patterns; DAST attacks the running application from the outside.

Think of it like

SAST is reading a building's blueprints for fire-safety violations. DAST is walking in and trying the doors.

Junior or senior?

Junior sounds like

Names the tools in the pipeline.

Senior sounds like

Talks about false positives and triage — the reason most SAST rollouts get ignored within a quarter.

Ask them

“How did your team handle the false positives from your security scanner?”