問題文
A tool reads uncompiled source, the libraries it references and the configuration files, then compares them against its own repository of known weaknesses for that language. Nothing has to be running. Which category does it fall under, and what does it require?
選択肢
- A tool of this description falls under the dynamic analysis category, and the precondition it imposes on the vulnerability run is the deployed service instance.
- A tool of this description falls under the static analysis category, and the precondition it imposes on the vulnerability run is the granted source access.
- A tool of this description falls under the composition analysis category, and the precondition it imposes on the vulnerability run is the resolved dependency manifest.
- A tool of this description falls under the interactive analysis category, and the precondition it imposes on the vulnerability run is the installed runtime agent.