Certified Application Security Engineer (CASE)

Inquire now

Duration 3 days – 21 hrs

 

Overview

 

The Certified Application Security Engineer (C|ASE) program by EC-Council is an advanced training that focuses on securing applications across the Software Development Lifecycle (SDLC). It provides developers, testers, and security professionals with in-depth knowledge and practical techniques to design, develop, test, and maintain secure applications. Participants will gain expertise in secure coding practices, application architecture, security requirements gathering, and advanced testing methodologies.

 

Objectives

 

  • Identify and mitigate application vulnerabilities and attack vectors.
  • Integrate security into every phase of the SDLC.
  • Apply secure coding standards for input validation, authentication, authorization, cryptography, session management, and error handling.
  • Conduct Static and Dynamic Application Security Testing (SAST & DAST).
  • Deploy applications securely and ensure long-term security mai

 

Audience

  • Software Developers (Java or .NET focus)
  • Application Security Engineers / Analysts
  • Software Testers and QA Professionals
  • Security Consultants and Auditors
  • System Architects involved in application design
  • Professionals seeking C|ASE certification

 

Prerequisites

  • Basic knowledge of programming (Java, .NET, or equivalent).
  • Familiarity with application development lifecycle.
  • Understanding of IT security fundamentals (recommended).

Course Content

 

Module 1: Understanding Application Security, Threats, and Attacks

 

  • Overview of Application Security
  • Common Vulnerabilities (OWASP Top 10)
  • Threat Modeling and Risk Analysis
  • Exploitation Techniques (SQL Injection, XSS, CSRF, etc.)
  • Case Studies of Real-World Breaches

 

Module 2: Security Requirements Gathering

 

  • Importance of Security in Requirements Phase
  • Identifying Security Goals and Constraints
  • Regulatory and Compliance Requirements (GDPR, HIPAA, PCI-DSS)
  • Security Requirements Traceability Matrix (SRTM)
  • Integrating Security in Agile and DevOps Environments

 

Module 3: Secure Application Design and Architecture

 

  • Principles of Secure Design
  • Defense in Depth and Layered Security
  • Secure Architectural Patterns (MVC, Microservices, Zero Trust)
  • Threat Modeling Tools (STRIDE, DREAD, PASTA)
  • Design Flaws vs Coding Flaws

 

Module 4: Secure Coding Practices – Input Validation

 

  • Input Validation Fundamentals
  • Whitelisting vs Blacklisting
  • Handling User Input and Sanitization
  • Preventing Injection Attacks (SQLi, Command Injection)
  • Secure File Uploads and Path Traversal Protection

]

Module 5: Secure Coding Practices – Authentication & Authorization

 

  • Strong Authentication Mechanisms (MFA, Tokens, SSO)
  • Secure Password Management and Storage
  • Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC)
  • Preventing Broken Authentication and Privilege Escalation
  • Session Hijacking Prevention

 

Module 6: Secure Coding Practices – Cryptography

 

  • Cryptographic Principles (CIA Triad, Hashing, Symmetric/Asymmetric Encryption)
  • Secure Use of Cryptographic APIs
  • Common Pitfalls (Hardcoded Keys, Weak Algorithms)
  • Secure Key Management Practices
  • Ensuring Data Integrity and Confidentiality

 

Module 7: Secure Coding Practices – Session Management

 

  • Secure Session Lifecycle (Creation, Maintenance, Destruction)
  • Secure Cookie Attributes (HttpOnly, Secure, SameSite)
  • Preventing Session Hijacking and Replay Attacks
  • Best Practices for Session IDs and Tokens
  • Timeout and Re-authentication Policies

 

Module 8: Secure Coding Practices – Error Handling

 

  • Importance of Secure Exception Handling
  • Avoiding Information Disclosure in Error Messages
  • Logging Best Practices (Centralized, Secure Logging)
  • Secure Debugging and Stack Trace Management
  • Failing Securely vs Failing Open

 

Module 9: Static and Dynamic Application Security Testing (SAST & DAST)

 

  • Introduction to Application Security Testing
  • Static Application Security Testing (Code Analysis, Tools like SonarQube, Checkmarx)
  • Dynamic Application Security Testing (Runtime Testing, Tools like Burp Suite, OWASP ZAP)
  • Automated vs Manual Testing
  • Integrating Testing into CI/CD Pipelines (DevSecOps)

 

Module 10: Secure Deployment and Maintenance

 

  • Secure Build and Deployment Processes
  • Hardening Application Servers and Containers
  • Secure Configuration Management
  • Patch Management and Continuous Updates
  • Monitoring and Incident Response for Applications
  • Post-Deployment Security Reviews and Audits

 

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy