When does static application security testing require access to source code?
only if following the Agile model
only when assessing regulatory compliance
always
never Explanation: