Concept and mechanism
Techniques observe different parts of a system. SAST analyzes code without requiring full application execution; DAST observes a runnable application; SCA examines components and dependencies. None automatically replaces the others or proves absence of business-logic flaws. A transitive library can appear in the lockfile without appearing in the direct list and needs version and usage analysis. For credentialed scans, confirm local checks actually ran. A complete target list does not guarantee complete coverage. Also distinguish component presence, vulnerability applicability, and exploitation demonstrated within authorized context.
Guided application
In the fictional exercise, fifteen of sixty hosts failed authentication. Credentialed coverage is forty-five of sixty, or seventy-five percent. Remaining hosts need completion rather than a “remediated” state. Elsewhere in the report, an old banner corresponds to a backported package. Link the advisory, installed release, and condition before reviewing the finding as a possible false positive. Retain evidence even when classification changes. When selecting NSE scripts, check behavior and scope: loading everything can include techniques beyond low-impact enumeration. For prioritization, record CVSS version and vector and add exposure and business context. The score communicates severity and assumptions; it does not directly convert into financial loss or guaranteed exploitation.
45 of 60 hosts with successful local checks: 75% credentialed coverage.
Common pitfalls
Ignored indirect dependency; attempted scan as complete; banner as patched state; every script as low impact.
Related topics: Scope, communication, and evidence · Reconnaissance and result interpretation · Web and API flaws and remediation
Connect each conclusion to method, coverage, and evidence.
Reference: Security testing and assessment · PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17