APURV
  • Home
  • Journey
  • Projects
  • Blogs
  • Interview
  • Exams
Resume
APURV

Building scalable, secure, and production-ready cloud infrastructure. Automation first.

NAVIGATION

HomeExperienceProjectsCertificationsSkills

TECH STACK

AWSGCPK8sCI/CDLinuxDocker

CONNECT

LinkedInGitHubEmailResume

© 2026 Apurv Gujjar. All rights reserved.
Apurv Gujjar
Apurv GujjarDevOps & Cloud Engineer
|Interview Documentation
Portfolio
Handbooks
🎯Linux🐙Git & GitHub🤖GitHub Actions🌐Networking☁AWS🛠Terraform🐳Docker☸Kubernetes📊Monitoring🛡DevSecOps💰Cost Optimization🚨Incident Scenarios👤HR & Behavioral☁GCP🐍Python
Interview DocumentationDevSecOpsCompare SAST, DAST, and IAST.
Back to all DevSecOps questions
Q2

Compare SAST, DAST, and IAST.

💬Answer
  • SAST (Static Application Security Testing): Analyzes source code or binaries without executing them (White-box testing) to identify coding errors, vulnerabilities, and credential leaks early.
  • DAST (Dynamic Application Security Testing): Analyzes a running application from the outside (Black-box testing) to discover runtime vulnerabilities, authentication weaknesses, and injection flaws.
  • IAST (Interactive Application Security Testing): Combines SAST and DAST by executing inside the application runtime using instrumented agents, analyzing code paths and inputs in real-time.

Related DevSecOps Questions

View All DevSecOpsQuestions →
Q1

What is DevSecOps?

Q3

What is Dependency Scanning?

Q4

What is an SBOM?

Q5

What is Supply Chain Security?

Apurv Gujjar - DevOps & Cloud Engineer
Created by

Apurv Gujjar

DevOps & Cloud Engineer

Specialized in:DevOpsAWSGCPKubernetesTerraformDocker
View Portfolio