For the complete documentation index, see llms.txt. This page is also available as Markdown.

Application & API Runtime Protection

Learn Application & API Runtime Protection through Harness University

Protection ensures that your applications and APIs remain resilient, compliant, and secure in production.

Go to Harness University for the full catalogue of courses and certifications.

Self-Paced Training Instructor-Led Training Certifications

Self-Paced Training

Free self-paced courses that you can consume on your own time.

Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

Application & API Runtime Protection - Developer

Application & API Runtime Protection - Developer badge

Product version: API & Application Runtime Protection Paid Plans

Assesses the fundamental skills to manage your posture with API & Application Runtime Protection projects.

Review Study Guide

Objective #
Description
Material

1

GraphQL-Based Dynamic API Ownership Assignment

1.1

Constructing and interpreting GraphQL createPolicy mutations for Static, Dynamic, and Regex-based policy assignments

1.2

Configuring RE2 regular expression patterns with specific capture group indices and fallback constants

1.3

Managing active ownership policies using getPolicies queries, updatePolicy mutations, and deletePolicies mutations

2

Edge Cluster Deployment & Routing

2.1

Configuring DNS vs. CDN routing models

2.2

Edge deployment service settings (idle timeouts, keep-alive)

2.3

HTTP/HTTPS Header configurations (max count, case insensitivity)

2.4

Multi-origin distribution and backend server configurations

2.5

Edge Cluster Deployment operational states (Requested, Blocked, Done)

2.6

Prerequisites for Edge deployment (DNS, routing, TLS)

3

High Availability & Failover Mechanics

3.1

Monitoring health using the Health Check URL

3.2

Traffic routing and behavior during localized failures

3.3

WAAP outage behaviors: Regional (partial) vs. Global (full) outages

3.4

Action on global outage: Block traffic to prevent breaches

3.5

Manual DNS intervention and bypass protocols

3.6

Support escalation and status monitoring

4

Core WAAP Capabilities & Bot Protection

4.1

Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections

4.2

Automated bot mitigation (credential stuffing, card testing, web scraping)

4.3

Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS

4.4

Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment

4.5

Identifying bot behaviors by examining aggregate patterns vs. isolated requests

4.6

Application-layer DDoS mitigation and anomaly-based rate limiting

5

Data Loss Prevention (DLP) & Zero Trust Policies

5.1

Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)

5.2

Dynamic conditions: Baseline traffic calculation for rate limiting

5.3

Static conditions vs. dynamic conditions

5.4

Data Protection: Mapping data access patterns to specific users and locations

5.5

Severity levels and enforcement actions (monitor, block, header injection)

5.6

Risks based on source types (anonymous VPNs, bots)

6

Threat Triage, Observability & Actor Investigation

6.1

Security Events module vs. Explorer view (data scope, use cases)

6.2

Grouping threat activities (by endpoint, rule, actor, or domain)

6.3

Analyzing threat evidence (request/response logs, IP reputation, country of origin)

6.4

Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)

6.5

Transitioning from passive monitoring to active response

6.6

Threat scoring based on severity and establishing a behavioral baseline

Register for Exam

Exam Details

The Harness Application & API Runtime Protection Developer Certification exam tests your knowledge and skills of the Application & API Runtime Protection module.

Prerequisites

  • Basic terminal skills

  • Basic understanding of Harness and API protection.

Exam Details

Exam Duration: 90 minutes

Question Type: Multiple choice

Here is the covered domain breakdown for your 30-question developer exam, showing how the weight is evenly distributed across the 5 core objective areas:

Covered Domain
Percentage

Edge Cluster Deployment & Routing

20.0%

High Availability & Failover Mechanics

20.0%

Core WAAP Capabilities & Bot Protection

20.0%

Data Loss Prevention (DLP) & Zero Trust Policies

20.0%

Threat Triage, Observability & Actor Investigation

20.0%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objectives

1

Edge Cluster Deployment & Routing

1.1

Configuring DNS vs. CDN routing models

1.2

Edge deployment service settings (idle timeouts, keep-alive)

1.3

HTTP/HTTPS Header configurations (max count, case insensitivity)

1.4

Multi-origin distribution and backend server configurations

1.5

Edge Cluster Deployment operational states (Requested, Blocked, Done)

1.6

Prerequisites for Edge deployment (DNS, routing, TLS)

2

High Availability & Failover Mechanics

2.1

Monitoring health using the Health Check URL

2.2

Traffic routing and behavior during localized failures

2.3

WAAP outage behaviors: Regional (partial) vs. Global (full) outages

2.4

Action on global outage: Block traffic to prevent breaches

2.5

Manual DNS intervention and bypass protocols

2.6

Support escalation and status monitoring

3

Core WAAP Capabilities & Bot Protection

3.1

Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections

3.2

Automated bot mitigation (credential stuffing, card testing, web scraping)

3.3

Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS

3.4

Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment

3.5

Identifying bot behaviors by examining aggregate patterns vs. isolated requests

3.6

Application-layer DDoS mitigation and anomaly-based rate limiting

4

Data Loss Prevention (DLP) & Zero Trust Policies

4.1

Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)

4.2

Dynamic conditions: Baseline traffic calculation for rate limiting

4.3

Static conditions vs. dynamic conditions

4.4

Data Protection: Mapping data access patterns to specific users and locations

4.5

Severity levels and enforcement actions (monitor, block, header injection)

4.6

Risks based on source types (anonymous VPNs, bots)

5

Threat Triage, Observability & Actor Investigation

5.1

Security Events module vs. Explorer view (data scope, use cases)

5.2

Grouping threat activities (by endpoint, rule, actor, or domain)

5.3

Analyzing threat evidence (request/response logs, IP reputation, country of origin)

5.4

Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)

5.5

Transitioning from passive monitoring to active response

5.6

Threat scoring based on severity and establishing a behavioral baseline


Next Steps

The Harness Application & API Runtime Protection Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

  1. Create an account in Harness University

  2. Register for an exam

  3. Take the exam

Register for Exam

Application & API Runtime Protection - Architect (BETA COMING SOON)

Application & API Runtime Protection - Architect (BETA COMING SOON) badge

Product version: Application & API Runtime Protection Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assess key technical job functions and advanced skills in design, implementation and management of Application & API Runtime Protection.

Last updated

Was this helpful?