A penetration tester is assessing a web application for vuln…
A penetration tester is assessing a web application for vulnerabilities. After initial manual testing, the pentester decides to use automated tools to speed up the process. The assessment includes scanning for exposed API keys, examining form fields, and looking for vulnerabilities such as SQL Injection and insecure server configurations. The pentester uses both SAST and DAST methods to test the application, and SCAP to ensure compliance with security standards. Which of the following actions best exemplifies the pentester’s dynamic testing process?