> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/university/api-application-protection.md).

# Application & API Runtime Protection

Secure production workloads and ensure continuous compliance with real-time threat protection for your applications and APIs.

Go to [Harness University](/university/readme.md) for the full catalogue of courses and certifications.

<a href="#self-paced-training" class="button secondary small">Self-Paced Training</a> <a href="#instructor-led-training" class="button secondary small">Instructor-Led Training</a> <a href="#certifications" class="button secondary small">Certifications</a>

## Self-Paced Training

Free self-paced courses that you can consume on your own time.

<table data-view="cards"><thead><tr><th></th><th></th><th><select><option value="IO6SHbQtJQDD" label="Free" color="blue"></option></select></th><th><select><option value="C9M8ozxbmkxn" label="Harness Platform" color="blue"></option></select></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Harness Platform Fundamentals</strong></td><td><p>Self-paced video course introducing the Harness Platform.</p><p><br><em>Product version: Free Plans of any module</em></p></td><td><span data-option="IO6SHbQtJQDD">Free</span></td><td><span data-option="C9M8ozxbmkxn">Harness Platform</span></td><td><a href="https://university-registration.harness.io/self-paced-training-platform-fundamentals">https://university-registration.harness.io/self-paced-training-platform-fundamentals</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr><tr><td><strong>Introduction to AI Agents</strong></td><td><p>Self-paced tidbit introducing the Custom AI Agents.</p><p><br><em>Product version: Paid Plans of any module</em></p></td><td><span data-option="IO6SHbQtJQDD">Free</span></td><td><span data-option="C9M8ozxbmkxn">Harness Platform</span></td><td><a href="https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents">https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr></tbody></table>

## Instructor-Led Training

Intensive two-day courses, designed for engineers looking to deepen their understanding and expertise in Harness.

<table data-view="cards"><thead><tr><th></th><th></th><th><select><option value="1q9UE527kfcd" label="Paid" color="blue"></option></select></th><th><select><option value="1BGe5ltwppZr" label="Harness Platform" color="blue"></option></select></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Introduction to the Harness Platform</strong></td><td><p>Self-paced, hands-on prerequisite course to all module-specific ILT courses.</p><p><br><em>Product version: Paid Plans of any module</em></p></td><td><span data-option="1q9UE527kfcd">Paid</span></td><td><span data-option="1BGe5ltwppZr">Harness Platform</span></td><td><a href="https://university-registration.harness.io/introduction-to-the-harness-platform">https://university-registration.harness.io/introduction-to-the-harness-platform</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr></tbody></table>

## Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

{% hint style="info" %}
**New to Harness?** Start with the **Developer** track. You can always move up as your responsibilities grow.
{% endhint %}

{% tabs %}
{% tab title="For Developer" %}

#### Prepare for the Exam

{% hint style="warning" %}
**Get Certified with Harness University!** Assess the fundamental skills to manage your security posture with API & Application Runtime Protection projects.

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2FumhYy7m2iS70UU8ejxrc%2Fimage.png?alt=media&amp;token=f74f21e6-defd-4ec6-8d4a-3d94a6c8aea8" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Runtime Protection Paid Plans</em></p>
{% endhint %}

#### Review Study Guide

| Objective # | Description                                                                          | Material                                                                                                                        |
| ----------- | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| **1**       | **Edge Cluster Deployment & Routing**                                                |                                                                                                                                 |
| 1.1         | Configuring DNS vs. CDN routing models                                               | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                       |
| 1.2         | Edge deployment service settings (idle timeouts, keep-alive)                         | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                       |
| 1.3         | HTTP/HTTPS Header configurations (max count, case insensitivity)                     | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment) / [Settings](https://docs.traceable.ai/docs/settings) |
| 1.4         | Multi-origin distribution and backend server configurations                          | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                       |
| 1.5         | Edge Cluster Deployment operational states (Requested, Blocked, Done)                | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                       |
| 1.6         | Prerequisites for Edge deployment (DNS, routing, TLS)                                | [Edge Cluster Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                       |
| **2**       | **High Availability & Failover Mechanics**                                           |                                                                                                                                 |
| 2.1         | Monitoring health using the Health Check URL                                         | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| 2.2         | Traffic routing and behavior during localized failures                               | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| 2.3         | WAAP outage behaviors: Regional (partial) vs. Global (full) outages                  | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| 2.4         | Action on global outage: Block traffic to prevent breaches                           | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| 2.5         | Manual DNS intervention and bypass protocols                                         | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| 2.6         | Support escalation and status monitoring                                             | [Health Check](https://docs.traceable.ai/docs/edge-deployment)                                                                  |
| **3**       | **Core WAAP Capabilities & Bot Protection**                                          |                                                                                                                                 |
| 3.1         | Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections      | [Web App & API Protection](https://docs.traceable.ai/docs/wap-api-protection)                                                   |
| 3.2         | Automated bot mitigation (credential stuffing, card testing, web scraping)           | [Bot Protection](https://docs.traceable.ai/docs/bot-protection) / [Bot Dashboard](https://docs.traceable.ai/docs/bot-dashboard) |
| 3.3         | Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS              | [Application and API Protection](https://docs.traceable.ai/docs/traceable-runtime-protection)                                   |
| 3.4         | Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment | [Application and API Protection](https://docs.traceable.ai/docs/traceable-runtime-protection)                                   |
| 3.5         | Identifying bot behaviors by examining aggregate patterns vs. isolated requests      | [Bot Protection](https://docs.traceable.ai/docs/bot-protection) / [Bot Actors](https://docs.traceable.ai/docs/bot-actors)       |
| 3.6         | Application-layer DDoS mitigation and anomaly-based rate limiting                    | [Web App & API Protection](https://docs.traceable.ai/docs/wap-api-protection)                                                   |
| **4**       | **Data Loss Prevention (DLP) & Zero Trust Policies**                                 |                                                                                                                                 |
| 4.1         | Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)    | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 4.2         | Dynamic conditions: Baseline traffic calculation for rate limiting                   | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 4.3         | Static conditions vs. dynamic conditions                                             | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 4.4         | Data Protection: Mapping data access patterns to specific users and locations        | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 4.5         | Severity levels and enforcement actions (monitor, block, header injection)           | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 4.6         | Risks based on source types (anonymous VPNs, bots)                                   | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| **5**       | **Threat Triage, Observability & Actor Investigation**                               |                                                                                                                                 |
| 5.1         | Security Events module vs. Explorer view (data scope, use cases)                     | [Security Events](https://docs.traceable.ai/docs/explore-data)                                                                  |
| 5.2         | Grouping threat activities (by endpoint, rule, actor, or domain)                     | [Threat Activity](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.3         | Analyzing threat evidence (request/response logs, IP reputation, country of origin)  | [Threat Activity](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.4         | Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)            | [Threat Actors](https://docs.traceable.ai/docs/threat-scoring)                                                                  |
| 5.5         | Transitioning from passive monitoring to active response                             | [Threat Actors](https://docs.traceable.ai/docs/threat-scoring)                                                                  |
| 5.6         | Threat scoring based on severity and establishing a behavioral baseline              |                                                                                                                                 |

<p align="right"><a href="https://university-registration.harness.io/certification-exam-harness-certified-application-api-runtime-protection-developer-certification" class="button primary small">Register For Exam</a></p>

#### Exam Details

The Harness Application & API Runtime Protection Developer Certification exam tests your knowledge and skills of the Application & API Runtime Protection module.

**Prerequisites**

* Basic terminal skills
* Basic understanding of Harness and API protection.

**Exam Details**

* Exam Duration: 90 minutes
* Question Type: Multiple choice

| Covered Domain                                         | Percentage |
| ------------------------------------------------------ | ---------- |
| **Edge Cluster Deployment & Routing**                  | 20%        |
| **High Availability & Failover Mechanics**             | 20%        |
| **Core WAAP Capabilities & Bot Protection**            | 20%        |
| **Data Loss Prevention (DLP) & Zero Trust Policies**   | 20%        |
| **Threat Triage, Observability & Actor Investigation** | 20%        |

**Exam Objectives**

<details>

<summary>List of Objectives</summary>

The following is a detailed list of exam objectives:

<table data-search="false"><thead><tr><th>#</th><th>Objectives</th></tr></thead><tbody><tr><td><strong>1</strong></td><td><strong>Edge Cluster Deployment &#x26; Routing</strong></td></tr><tr><td>1.1</td><td>Configuring DNS vs. CDN routing models</td></tr><tr><td>1.2</td><td>Edge deployment service settings (idle timeouts, keep-alive)</td></tr><tr><td>1.3</td><td>HTTP/HTTPS Header configurations (max count, case insensitivity)</td></tr><tr><td>1.4</td><td>Multi-origin distribution and backend server configurations</td></tr><tr><td>1.5</td><td>Edge Cluster Deployment operational states (Requested, Blocked, Done)</td></tr><tr><td>1.6</td><td>Prerequisites for Edge deployment (DNS, routing, TLS)</td></tr><tr><td><strong>2</strong></td><td><strong>High Availability &#x26; Failover Mechanics</strong></td></tr><tr><td>2.1</td><td>Monitoring health using the Health Check URL</td></tr><tr><td>2.2</td><td>Traffic routing and behavior during localized failures</td></tr><tr><td>2.3</td><td>WAAP outage behaviors: Regional (partial) vs. Global (full) outages</td></tr><tr><td>2.4</td><td>Action on global outage: Block traffic to prevent breaches</td></tr><tr><td>2.5</td><td>Manual DNS intervention and bypass protocols</td></tr><tr><td>2.6</td><td>Support escalation and status monitoring</td></tr><tr><td><strong>3</strong></td><td><strong>Core WAAP Capabilities &#x26; Bot Protection</strong></td></tr><tr><td>3.1</td><td>Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections</td></tr><tr><td>3.2</td><td>Automated bot mitigation (credential stuffing, card testing, web scraping)</td></tr><tr><td>3.3</td><td>Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS</td></tr><tr><td>3.4</td><td>Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment</td></tr><tr><td>3.5</td><td>Identifying bot behaviors by examining aggregate patterns vs. isolated requests</td></tr><tr><td>3.6</td><td>Application-layer DDoS mitigation and anomaly-based rate limiting</td></tr><tr><td><strong>4</strong></td><td><strong>Data Loss Prevention (DLP) &#x26; Zero Trust Policies</strong></td></tr><tr><td>4.1</td><td>Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)</td></tr><tr><td>4.2</td><td>Dynamic conditions: Baseline traffic calculation for rate limiting</td></tr><tr><td>4.3</td><td>Static conditions vs. dynamic conditions</td></tr><tr><td>4.4</td><td>Data Protection: Mapping data access patterns to specific users and locations</td></tr><tr><td>4.5</td><td>Severity levels and enforcement actions (monitor, block, header injection)</td></tr><tr><td>4.6</td><td>Risks based on source types (anonymous VPNs, bots)</td></tr><tr><td><strong>5</strong></td><td><strong>Threat Triage, Observability &#x26; Actor Investigation</strong></td></tr><tr><td>5.1</td><td>Security Events module vs. Explorer view (data scope, use cases)</td></tr><tr><td>5.2</td><td>Grouping threat activities (by endpoint, rule, actor, or domain)</td></tr><tr><td>5.3</td><td>Analyzing threat evidence (request/response logs, IP reputation, country of origin)</td></tr><tr><td>5.4</td><td>Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)</td></tr><tr><td>5.5</td><td>Transitioning from passive monitoring to active response</td></tr><tr><td>5.6</td><td>Threat scoring based on severity and establishing a behavioral baseline</td></tr></tbody></table>

***

</details>

**Next Steps**

The Harness Application & API Runtime Protection Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

1. Create an account in Harness University.
2. Register for an exam.
3. Take the exam.

<p align="right"><a href="https://university-registration.harness.io/certification-exam-harness-certified-application-api-runtime-protection-developer-certification" class="button primary small">Register For Exam</a></p>
{% endtab %}

{% tab title="For Administrator" %}

### Application & API Runtime Protection - Administrator&#x20;

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

{% hint style="warning" %}
**Get Certified with Harness University!** Assess the fundamental skills to deploy and maintain Application & API Runtime Protection projects and the overall Harness Platform.

<p align="center"></p>

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2FIrQnjdTJDVwMTUC30zQ3%2Fimage.png?alt=media&amp;token=f895a64d-9b2e-4605-aa0b-c8f7073b6da1" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Runtime Protection Paid Plans</em></p>
{% endhint %}
{% endtab %}

{% tab title="For Architect" %}

### Application & API Runtime Protection - Architect

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

{% hint style="warning" %}
**Get Certified with Harness University!** Assess key technical job functions and advanced skills in the design, implementation, and management of Application & API Runtime Protection.

<p align="center"></p>

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2FVECX0AmOPcZZD73my6yo%2Fimage.png?alt=media&amp;token=e8f3adf5-86bd-440d-bd49-931d3517f4a1" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Runtime Protection Paid Plans</em></p>
{% endhint %}
{% endtab %}
{% endtabs %}

{% @harness-feedback/feedback module="university" pagePath="university/api-application-protection" %}
