QuestionQ23

Security Engineering

A developer receives feedback about code quality and efficiency. The developer needs to identify and resolve the following coding issues before submitting the code changes for peer review:

• Indexing beyond arrays

• Dereferencing null pointers

• Potentially dangerous data type combos

• Unreachable code

• Non-portable constructs

Which of the following would be most appropriate for the developer to use in this situation?

Explanation

Linting is static code analysis that runs on source code before compilation and detects the exact issues listed: array indexing errors, null pointer dereferences, unsafe type combinations, unreachable code, and non-portable constructs. It runs locally during development, making it ideal for pre-review quality checks. SBOM catalogs dependencies; DAST tests running applications; branch protection enforces workflow controls; SCA identifies third-party vulnerabilities.

Community Discussion

No comments yet. Be the first to start the discussion!