When does static application security testing require access to source code?
only if following the Agile model
never Explanation:
only when assessing regulatory compliance
always