/CertifiedAppsecPractitioner

Since the SecOps Group has offered free certification to Certified Appsec Practitioner I will be creating notes here. I will be working on the Certified Appsec Practitioner.

Certified Appsec Practitioner (CAP)

Since the SecOps Group came up with a voucher that offered free certification to Certified Appsec Practitioner I will be creating notes here. I will be working on the Certified Appsec Practitioner.

The Course Contents for Certified Appsec Practitioner are as follows:

  1. Input Validation Mechanisms

2. Cross-Site Scripting

3. SQL Injection

4. XML External Entity attack

5. Cross-Site Request Forgery

6. Encoding, Encryption, and Hashing

7. Authentication related Vulnerabilities

8. Understanding of OWASP Top 10 Vulnerabilities

9. Security Best Practices and Hardening Mechanisms.

  1. TLS security
  1. Server-Side Request Forgery
  2. Authorization and Session Management related flaws –
  1. Insecure File Uploads
  2. Code Injection Vulnerabilities
  3. Business Logic Flaws
  4. Directory Traversal Vulnerabilities
  5. Security Misconfigurations.
  6. Information Disclosure.
  7. Vulnerable and Outdated Components.
  8. Common Supply Chain Attacks and Prevention Methods.

We will be following each of the above topics and studying them in detail.