ISTQB · Topic 5 of 15
Application Security Testing
White-box, black-box, and grey-box approaches at application level. Source-aware fuzzing.
6 lessons180 questions
What this topic covers
- 01Abuse Cases and Attack Trees for Security Test Design360m
- 02CVE, CVSS, DAST, Fuzzing, and Cryptographic Failures480m
- 03Hardcoded Credentials, IAM Testing, Injection, and More480m
- 04NVD, OWASP Top 10, PASTA, and Platform-Specific Vulnerabilities600m
- 05SAST, SCA, SBOM, and Supply Chain Security Testing480m
- 06Synthetic Data, IAST, DREAD, and Shift-Left Security Testing480m
Other topics in CT-STE — Security Test Engineer
Introduction to Security Test Engineering6 lessonsFundamentals of Security Testing4 lessonsThreat Modeling & Risk Assessment6 lessonsSecurity Test Design5 lessonsSpecific Security Test Topics8 lessonsSecurity Testing Tools7 lessonsSecurity Test Automation & CI/CD Integration6 lessonsSecurity Test Implementation and Execution7 lessonsSecurity Test Analysis and Reporting4 lessonsInfrastructure & Network Testing6 lessonsCryptography & Data Protection Testing6 lessonsSecurity Testing as Part of an ISMS4 lessonsSecurity Test Strategy and Planning5 lessonsStandards, Regulations, and Compliance4 lessons