This document discusses interactive application security testing (IAST) as a solution for mobile security testing. IAST analyzes applications in an instrumented environment to detect potential vulnerabilities by observing application behavior. It allows testing both the mobile application and some backend services simultaneously. IAST is presented as easier to use than static or dynamic application security testing alone, providing more actionable results while testing both the native mobile app layer and elements of the backend. The document outlines pros and cons of different testing strategies and emphasizes that IAST enables testing mobile apps and parts of the backend at the same time with ease of use.