Certified Application Security Engineer – Self-Paced (Incl. Exam Voucher)
Type
Skill Level
Available dates
Learning Path
Virtual
Duration
1 Day
LEARNING PATH
SKILL LEVEL
DURATION
AVAILABLE DATES
Choose date
R10 400,00
Price excluding VAT
Introduction
The Certified Application Security Engineer (CASE) Java focuses on secure application software development processes. It is a, hands-on, comprehensive application security course that will help you create a secure application software. This course encompasses security activities involved in all phases of the Secure Software Development Lifecycle (SDLC): planning, creating, testing, and deploying an application.
Unlike other application security trainings, CASE goes beyond just the guidelines on secure coding practices to include secure requirement gathering, robust application design, and handling security issues in post development phases of application development.
The CASE certification exam and training program prepare application security engineers, analysts, testers, and anyone with exposure to any phase of SDLC to build secure applications that are robust enough to meet today’s challenging operational environment by focusing not just on secure coding, but much more.
This makes CASE one of the most comprehensive certifications on the market today. It’s desired by software application engineers, analysts, testers globally, and respected by hiring authorities.
Audience profile
This course is specifically designed for:
- Java Developers
- Individuals who want to become application security engineers/analysts/testers
- Individuals involved in the role of developing, testing, managing, or protecting Java based applications
Pre-requisites
- Minimum of 2 years of experience
What is EC-Council iLearn?
iLearn is EC Council’s online, self-paced option which means that all of the same modules taught in the live course are recorded and presented in a streaming video format. A certification candidate can set their own learning pace by pausing the lectures and returning to their studies as their schedule permits! This all-inclusive training program provides the benefits of classroom training at your own pace.
What is included?
- Streaming video training modules – 1 year access
- Official EC-Council E-Courseware – 1 year access
- iLabs, Virtual Lab Platform – 6 months access
- One Certification exam voucher
- One Certificate of Attendance
How to Access the iLearn Portal?
All learning resources will be released directly to the delegate and a notification will be shared via email after your booking is complete. You may then login anytime at by following this link.
Course objectives
Upon completing this course, the learner will understand the following:
- Personal Computer Security
- In-depth understanding of secure SDLC and secure SDLC models
- Knowledge of OWASP Top 10, threat modelling, SAST and DAST
- Capturing security requirements of an application in development
- Defining, maintaining, and enforcing application security best practices
- Performing manual and automated code review of application
- Conducting application security testing for web applications to assess the vulnerabilities
- Driving development of a holistic application security program
- Rating the severity of defects and publishing comprehensive reports, detailing associated risks and mitigations
- Working in teams to improve security posture, application security scanning technologies such as AppScan, Fortify, WebInspect, static application security testing (SAST), dynamic application security testing (DAST), single sign-on, and encryption
- Following secure coding standards that are based on industry-accepted best practices such as OWASP Guide, or CERT Secure Coding to address common coding vulnerabilities
- Creating a software source code review process that is a part of the development cycles (SDLC, Agile, CI/CD)
Course content
Module 1: Understanding Application Security, Threats, and Attacks | |
|
|
|
|
|
|
|
|
Module 2: Security Requirements Gathering | |
|
|
|
|
|
|
Module 3: Secure Application Design and Architecture | |
|
|
|
|
|
|
|
|
Module 4: Secure Coding Practices for Input Validation | |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Module 5: Secure Coding Practices for Authentication and Authorization | |
|
|
|
|
|
|
|
|
|
|
|
|
Module 6: Secure Coding Practices for Cryptography | |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Module 7: Secure Coding Practices for Session Management | |
|
|
|
|
|
|
|
|
Module 8: Secure Coding Practices for Error Handling | |
|
|
|
|
|
|
|
|
|
|
Module 9: Static and Dynamic Application Security Testing (SAST & DAST) | |
|
|
|
|
|
|
|
|
Module 10: Secure Deployment and Maintenance | |
|
|
|
|
|
|
|
|
|
Associated Certification Exam
The CASE exam can be challenged after attending the official CASE training. Candidates that successfully pass the exam will receive their CASE certificate and membership privileges. Members are expected to adhere to the policies of EC-Council’s Continuing Education Requirements.
To be eligible to challenge the CASE Exam, the candidate must either:
- Complete the official EC-Council CASE training through an accredited EC-Council Partner (Accredited Training Centre/ iWeek/ iLearn) (All candidates are required to pay the USD100 application fee unless your training fee already includes this)
- Be an ECSP (.NET/ Java) member in good standing (you need not pay a duplicate application fee, as this fee has already been paid)
- Have a minimum of 2 years working experience in InfoSec/ Software domain (you will need to pay USD 100 as a non-refundable application fee)
- Have any other industry equivalent certifications such as GSSP .NET/Java (you will need to pay USD 100 as a non-refundable application fee
Exam Details | Certified Applications Security Engineer |
Exam Title | CASE (Java) |
Number of Questions/Practical Challenges | 50 Questions |
Test Duration | 2 Hours |
Test Format | Multiple Choice Questions |
Test Delivery | ECC EXAM portal |
Availability | ECC EXAM |
Exam Prefix | 312-96 |
Passing Score | 70% |
On successful completion of this course students will receive a Torque IT attendance certificate.
Note:
When you attend any authorised EC Council training course at Torque IT you will receive the associated examination voucher as part of your course material. Your certification examination voucher can be used to book and pay for your certification examination at an Authorised EC Council Testing Center (ETC) only. If you are not able to sit your certification examination at Torque IT, and you have no other ETC locally available, you do have the ability to convert your examination voucher into a Pearson VUE examination voucher (Remote Procuring Services), at an additional cost.
EC-Council Overview
To beat a hacker, you need to think like one…
Ethical Hacking is the process of proactively penetrating systems, to which one has official permission to do so, with a view to determining whether vulnerabilities exist and then to undertake the necessary preventive, corrective, and protective countermeasures before an actual compromise to the systems can occur.
Torque IT’s authorised EC-Council training, and associated certification, solutions empower you to identify vulnerabilities and to assess the security posture of target systems. EC-Council certifications are universally recognised as demonstrating a high level of expertise and credibility for individuals and the organisations that employ them.
Torque IT being an EC-Council Accredited Training Center (ATC) has been the recipient of EC-Council’s most prestigious ATC of the year awards for 2016, 2014 and EC-Council’s Circle of Excellence Awards for 2015.
These achievements reflect our commitment to providing you with quality skills development, enablement, training, and certification solutions that demonstrate exceptional quality, depth and breadth.