Description
SEC522: Application Security: Securing Web Applications, APIs, and Microservices. This course is an advanced, hands-on training for security professionals focused on securing critical HTTP-based technologies. This protocol forms the foundation of cloud computing communications, application programming interfaces (APIs), microservices, and AI platforms, and mastering its security is essential for defending modern digital infrastructure. With over 20 hands-on labs and a defense challenge, this course provides the skills needed to identify vulnerabilities, implement defenses, and secure web protocols. In addition to covering well-known threats such as the OWASP Top 10, the course content also includes emerging attacks against HTTP-based systems, preparing participants for the GWEB Specialist certification. As organizations move toward cloud platforms, microservice architectures, and AI integration, the HTTP security principles taught in this course have immediate and critical application in protecting the entire technology ecosystem. Participants will learn how to identify vulnerabilities early in development, report risks, and implement security controls in web applications, RESTful and GraphQL APIs, and AI platform endpoints.
What you will learn
- Defend against attacks: Defend against OWASP Top 10 attacks and input-related vulnerabilities such as SQL injection, XSS, and CSRF.
- Increase infrastructure security: Strengthen infrastructure security and configuration management for stronger protection.
- Secure Integration: Securely integrate cloud components, microservices, and AI tools into modern applications.
- Strengthen authentication and authorization: Strengthen authentication and authorization using OAuth, SAML, SSO, and passwordless mechanisms.
- Improve web security: Improve web security by using protected HTTP headers and cross-domain request controls.
- Protect APIs: Protect your SOAP, REST, and GraphQL APIs from emerging threats.
- Prepare for Certification: This course prepares students for GWEB certification.
This course is suitable for people who:
- Developers and engineers: To automate repetitive tasks, improve code quality, and simplify deployment pipelines.
- DevOps professionals: To use GitHub Actions to build, monitor, and manage CI/CD pipelines for teams of any size.
- IT and system administrators: To implement efficient workflows for application delivery and infrastructure automation.
- Project managers and team leaders: To understand CI/CD pipelines and oversight to better manage development teams and project lifecycles.
- Students and enthusiasts: To get started with automation and deployment using the GitHub ecosystem.
Course Description SEC522: Application Security: Securing Web Applications, APIs, and Microservices
- Publisher: SANS
- Lecturer: Jason Lam , Dr. Johannes Ullrich
- Training level: Beginner to advanced
- Training duration: 23 hours and 51 minutes
- Number of lessons: 886
Course headings

Course Prerequisites SEC522: Application Security: Securing Web Applications, APIs, and Microservices
- This class requires a basic understanding of web application technology and concepts such as HTML and JavaScript. To maximize the benefit for a wider range of audiences, the discussions in this course will be programming-language-agnostic. Attendees should have some understanding of concepts like databases (SQL) and scripting languages used in modern web applications.
Course images

Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
PDF file download link
USB file download link
Video file download link
File(s) password: www.downloadly.ir
File size
76 MB, 6.9 GB, 3.08 GB