> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/university/api-application-testing.md).

# Application & API Security Testing

Analyze API traffic and mitigate exposure risks with continuous vulnerability scanning and automated authentication controls.

Go to [Harness University](/university/readme.md) for the full catalogue of courses and certifications.

<a href="#self-paced-training" class="button secondary small">Self-Paced Training</a> <a href="#instructor-led-training" class="button secondary small">Instructor-Led Training</a> <a href="#certifications" class="button secondary small">Certifications</a>

## Self-Paced Training

Free self-paced courses that you can consume on your own time.

<table data-view="cards"><thead><tr><th></th><th></th><th><select><option value="IO6SHbQtJQDD" label="Free" color="blue"></option></select></th><th><select><option value="wvnD4eKPSUkb" label="Harness Platform" color="blue"></option></select></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Harness Platform Fundamentals</strong></td><td><p>Self-paced video course introducing the Harness Platform.</p><p><br><em>Product version: Free Plans of any module</em></p></td><td><span data-option="IO6SHbQtJQDD">Free</span></td><td><span data-option="wvnD4eKPSUkb">Harness Platform</span></td><td><a href="https://university-registration.harness.io/self-paced-training-platform-fundamentals">https://university-registration.harness.io/self-paced-training-platform-fundamentals</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr><tr><td><strong>Introduction to AI Agents</strong></td><td><p>Self-paced tidbit introducing the Custom AI Agents.</p><p><br><em>Product version: Paid Plans of any module</em></p></td><td><span data-option="IO6SHbQtJQDD">Free</span></td><td><span data-option="wvnD4eKPSUkb">Harness Platform</span></td><td><a href="https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents">https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr></tbody></table>

## Instructor-Led Training

Intensive two-day courses, designed for engineers looking to deepen their understanding and expertise in Harness.

<table data-view="cards"><thead><tr><th></th><th></th><th><select><option value="1q9UE527kfcd" label="Paid" color="blue"></option></select></th><th><select><option value="3SFeOHc7XILr" label="Harness Platform" color="blue"></option></select></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Introduction to the Harness Platform</strong></td><td><p>Self-paced, hands-on prerequisite course to all module-specific ILT courses.</p><p><br><em>Product version: Paid Plans of any module</em></p></td><td><span data-option="1q9UE527kfcd">Paid</span></td><td><span data-option="3SFeOHc7XILr">Harness Platform</span></td><td><a href="https://university-registration.harness.io/introduction-to-the-harness-platform">https://university-registration.harness.io/introduction-to-the-harness-platform</a></td><td><a href="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F7QGXbawYR4BP0qizpMwP%2Fplatform.png?alt=media&amp;token=c2620ec1-3d29-479e-bd7c-74a979590f65">platform.png</a></td></tr></tbody></table>

## Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

{% hint style="info" %}
**New to Harness?** Start with the **Developer** track. You can always move up as your responsibilities grow.
{% endhint %}

{% tabs %}
{% tab title="For Developer" %}

#### Prepare for the Exam

{% hint style="warning" %}
**Get Certified with Harness University!** Assess the fundamental skills to manage your security posture with API & Application Security Testing projects.

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2F1XFestsdF685FbvqwbYg%2Fimage.png?alt=media&amp;token=fc3ef43c-ca46-4214-954d-172c8baef185" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Security Testing Paid Plans</em></p>
{% endhint %}

#### Review Study Guide

| Objective # | Description                                          | Material                                                                                                                                                          |
| ----------- | ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **1**       | **Core Concepts and Architecture of AST**            |                                                                                                                                                                   |
| 1.1         | Foundations of API Security Testing                  | [API Security Testing](https://docs.traceable.ai/docs/api-testing), [Application Security Testing](https://docs.traceable.ai/docs/api-testing)                    |
| 1.2         | AST Architecture and Components                      | [Getting Started with AST](https://docs.traceable.ai/docs/ast-getting-started), [AST Basics and Workflow](https://docs.traceable.ai/docs/ast-basics-and-workflow) |
| **2**       | **Scans, Traffic Types, and API Coverage**           |                                                                                                                                                                   |
| 2.1         | Traffic Selection and Characteristics                | [Understanding Scans and Traffic Types](https://docs.traceable.ai/docs/ast-scans)                                                                                 |
| 2.2         | Scan Reachability and Validation                     | [Scan Details](https://docs.traceable.ai/docs/ast-scan-details)                                                                                                   |
| 2.3         | Monitoring Scanned APIs and Coverage                 | [Scan Details](https://docs.traceable.ai/docs/ast-scan-details)                                                                                                   |
| **3**       | **Scan Creation and Execution Controls**             |                                                                                                                                                                   |
| 3.1         | Configuring Scan Parameters                          | [Creating a Scan](https://docs.traceable.ai/docs/creating-scan)                                                                                                   |
| 3.2         | Incremental Scanning Mechanics                       | [Creating a Scan](https://docs.traceable.ai/docs/creating-scan)                                                                                                   |
| 3.3         | Managing Active Scans                                | [Creating a Scan](https://docs.traceable.ai/docs/creating-scan)                                                                                                   |
| **4**       | **Environment Configurations and Security Controls** |                                                                                                                                                                   |
| 4.1         | Managing AST and Replay Environment States           | [Environment Config](https://docs.traceable.ai/docs/environment-config)                                                                                           |
| 4.2         | Granular Replay Filtering                            | [Environment Config](https://docs.traceable.ai/docs/environment-config)                                                                                           |
| 4.3         | RBAC Configuration Constraints                       | [Environment Config](https://docs.traceable.ai/docs/environment-config)                                                                                           |
| **5**       | **AST Policies and Attack Configurations**           |                                                                                                                                                                   |
| 5.1         | Policy Selections and Creation                       | [Policies](https://docs.traceable.ai/docs/ast-policies)                                                                                                           |
| 5.2         | Attack Depth and Safety Levels                       | [Policies](https://docs.traceable.ai/docs/ast-policies)                                                                                                           |
| 5.3         | Mapping Attack Categories                            | [Policies](https://docs.traceable.ai/docs/ast-policies), [Vulnerability Types](https://docs.traceable.ai/docs/vulnerability-types)                                |
| **6**       | **Scan Authentication Hook Integration**             |                                                                                                                                                                   |
| 6.1         | Scan Authentication Context and Mechanisms           | [Authentication](https://docs.traceable.ai/docs/ast-authentication)                                                                                               |
| 6.2         | Setup Configurations and AI Adaptability             | [Authentication](https://docs.traceable.ai/docs/ast-authentication)                                                                                               |
| 6.3         | Authorization Roles                                  | [Authentication](https://docs.traceable.ai/docs/ast-authentication)                                                                                               |
| **7**       | **CLI and Runner Operations**                        |                                                                                                                                                                   |
| 7.1         | Active Runners vs. Synchronous CLI                   | [Runners and CLI](https://docs.traceable.ai/docs/runners)                                                                                                         |
| 7.2         | CLI Configurations and Files                         | [Traceable CLI Config](https://docs.traceable.ai/docs/traceable-cli)                                                                                              |
| 7.3         | Local Logging Modes and Debugging                    | [Traceable CLI Config](https://docs.traceable.ai/docs/traceable-cli)                                                                                              |
| **8**       | **Issue Management, Customization, and Reporting**   |                                                                                                                                                                   |
| 8.1         | Finding Investigation and Auto-Resolution            | [AST Issues Overview](https://docs.traceable.ai/docs/ast-issues-overview)                                                                                         |
| 8.2         | Reporting Analysis and Action Execution              | [AST Reports](https://docs.traceable.ai/docs/ast-reports)                                                                                                         |
| 8.3         | Assertions, Mutations, and Overrides                 | [Mutation and Assertion Overrides](https://docs.traceable.ai/docs/mutation-and-assertion-overrides), [Plugins](https://docs.traceable.ai/docs/test-custom-plugin) |

<p align="right"><a href="https://university-registration.harness.io/certification-exam-harness-certified-application-api-security-testing-developer-certification" class="button primary small">Register For Exam</a></p>

#### Exam Details

The Harness API & Application Security Testing Developer Certification exam tests your knowledge and skills of the API & Application Security Testing module.

**Prerequisites**

* Basic terminal skills
* Basic understanding of Harness and API protection.

**Exam Details**

* Exam Duration: 90 minutes
* Question Type: Multiple choice

<table data-search="false"><thead><tr><th>Covered Domain</th><th>Percentage</th></tr></thead><tbody><tr><td><strong>Core Concepts and Architecture of AST</strong></td><td>12.5%</td></tr><tr><td><strong>Scans, Traffic Types, and API Coverage</strong></td><td>12.5%</td></tr><tr><td><strong>Scan Creation and Execution Controls</strong></td><td>12.5%</td></tr><tr><td><strong>Environment Configurations and Security Controls</strong></td><td>12.5%</td></tr><tr><td><strong>AST Policies and Attack Configurations</strong></td><td>12.5%</td></tr><tr><td><strong>Scan Authentication Hook Integration</strong></td><td>12.5%</td></tr><tr><td><strong>CLI and Runner Operations</strong></td><td>12.5%</td></tr><tr><td><strong>Issue Management, Customization, and Reporting</strong></td><td>12.5%</td></tr></tbody></table>

**Exam Objectives**

<details>

<summary>List of Objectives</summary>

The following is a detailed list of exam objectives:

<table data-search="false"><thead><tr><th>Objective #</th><th>Description</th></tr></thead><tbody><tr><td><strong>1</strong></td><td><strong>Core Concepts and Architecture of AST</strong></td></tr><tr><td>1.1</td><td>Foundations of API Security Testing</td></tr><tr><td>1.2</td><td>AST Architecture and Components</td></tr><tr><td><strong>2</strong></td><td><strong>Scans, Traffic Types, and API Coverage</strong></td></tr><tr><td>2.1</td><td>Traffic Selection and Characteristics</td></tr><tr><td>2.2</td><td>Scan Reachability and Validation</td></tr><tr><td>2.3</td><td>Monitoring Scanned APIs and Coverage</td></tr><tr><td><strong>3</strong></td><td><strong>Scan Creation and Execution Controls</strong></td></tr><tr><td>3.1</td><td>Configuring Scan Parameters</td></tr><tr><td>3.2</td><td>Incremental Scanning Mechanics</td></tr><tr><td>3.3</td><td>Managing Active Scans</td></tr><tr><td><strong>4</strong></td><td><strong>Environment Configurations and Security Controls</strong></td></tr><tr><td>4.1</td><td>Managing AST and Replay Environment States</td></tr><tr><td>4.2</td><td>Granular Replay Filtering</td></tr><tr><td>4.3</td><td>RBAC Configuration Constraints</td></tr><tr><td><strong>5</strong></td><td><strong>AST Policies and Attack Configurations</strong></td></tr><tr><td>5.1</td><td>Policy Selections and Creation</td></tr><tr><td>5.2</td><td>Attack Depth and Safety Levels</td></tr><tr><td>5.3</td><td>Mapping Attack Categories</td></tr><tr><td><strong>6</strong></td><td><strong>Scan Authentication Hook Integration</strong></td></tr><tr><td>6.1</td><td>Scan Authentication Context and Mechanisms</td></tr><tr><td>6.2</td><td>Setup Configurations and AI Adaptability</td></tr><tr><td>6.3</td><td>Authorization Roles</td></tr><tr><td><strong>7</strong></td><td><strong>CLI and Runner Operations</strong></td></tr><tr><td>7.1</td><td>Active Runners vs. Synchronous CLI</td></tr><tr><td>7.2</td><td>CLI Configurations and Files</td></tr><tr><td>7.3</td><td>Local Logging Modes and Debugging</td></tr><tr><td><strong>8</strong></td><td><strong>Issue Management, Customization, and Reporting</strong></td></tr><tr><td>8.1</td><td>Finding Investigation and Auto-Resolution</td></tr><tr><td>8.2</td><td>Reporting Analysis and Action Execution</td></tr><tr><td>8.3</td><td>Assertions, Mutations, and Overrides</td></tr></tbody></table>

***

</details>

**Next Steps**

The Harness Application & API Security Testing Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

1. Create an account in Harness University.
2. Register for an exam.
3. Take the exam.

<p align="right"><a href="https://university-registration.harness.io/certification-exam-harness-certified-application-api-security-testing-developer-certification" class="button primary small">Register For Exam</a></p>
{% endtab %}

{% tab title="For Administrator" %}

### Application & API Security Testing - Administrator

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

{% hint style="warning" %}
**Get Certified with Harness University!** Assess the fundamental skills to deploy and maintain Application & API Runtime Protection projects and the overall Harness Platform.

<p align="center"></p>

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2FeZpRBMyTFffVhcw2IEHN%2Fimage.png?alt=media&amp;token=1da0c962-5bfa-44a6-af6c-0fd52f2daf55" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Security Testing Paid Plans</em></p>
{% endhint %}
{% endtab %}

{% tab title="For Architect" %}

### Application & API Security Testing - Architect

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

{% hint style="warning" %}
**Get Certified with Harness University!** Assess key technical job functions and advanced skills in design, implementation and management of Application & API Security Testing.

<p align="center"></p>

<p align="center"><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2FoJqNIdKKlIj69Rh5t68R%2Fimage.png?alt=media&amp;token=f025bf4a-29de-4354-b23c-23185fe2616f" alt=""></p>

<p align="center"><br><em>Product version<strong>:</strong> Harness API &#x26; Application Security Testing Paid Plans</em></p>
{% endhint %}
{% endtab %}
{% endtabs %}

{% @harness-feedback/feedback module="university" pagePath="university/api-application-testing" %}
