Tab navigation
- Overview
- Objectives- selected tab,
- Test preparation
Section 1 - AppScan Source Edition Overview and Sales (35%)
- Explain the critical role of application security
- Explain the differences between static and dynamic analysis
- Understand different deployment and workflow configurations
- Know the main components of AppScan Source Edition
- List features and characteristics of AppScan Source Edition
- Understand scenarios for which AppScan Source is the ideal solution
- Explain the different professional service offerings
- Understand the competitive landscape and the advantages AppScan source has over major competitors
- Know the best way to respond to client questions
Section 2 - Essential Technical Knowledge of AppScan Source Edition (40%)
- Install AppScan Source
- Configure AppScan Source
- Scan your application using AppScan Source for Security
- Use filters, validators, and custom rules to ensure actionable results
- Understand AppScan Source terminology
- Understand the vulnerability matrix
- Know the purposes of different views in AppScan Source
- Obtain Remediation information and support to fix vulnerabilities
Section 3 - Web Application Security Essentials (15%)
- Understand the basics of Web application security
- Understand WASC Threat Classes
- Understand the OWASP Top 10 Web application security vulnerabilities
- Identify common attack types
- Understand threat modeling
Section 4 - Delivering Security-Rich Web Applications (10%)
- Understand the Web application lifecycle
- Ensure security at all layers (eagle's view, single transaction, session, application, etc.)
- Secure the Web application environment
- Secure third-party tools
