> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/university/readme/api-application-protection.md).

# Application & API Runtime Protection

Learn Application & API Runtime Protection through Harness University

Protection ensures that your applications and APIs remain resilient, compliant, and secure in production.

Go to [Harness University](/university/readme.md) for the full catalogue of courses and certifications.

## Self-Paced Training

Free self-paced courses that you can consume on your own time.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Harness Platform Fundamentals</strong></td><td>Self-paced video course introducing the Harness Platform.<br><em>Product version: Free Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-platform-fundamentals">https://university-registration.harness.io/self-paced-training-platform-fundamentals</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to AI Agents</strong></td><td>Self-paced tidbit introducing the Custom AI Agents.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents">https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents</a></td></tr></tbody></table>

## Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to the Harness Platform</strong></td><td>Self-paced hands-on, prerequisite course to all module-specific ILT courses.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/introduction-to-the-harness-platform">https://university-registration.harness.io/introduction-to-the-harness-platform</a></td></tr></tbody></table>

## Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

{% tabs %}
{% tab title="For Developer" %}

### Application & API Runtime Protection - Developer

![Application & API Runtime Protection - Developer badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-3c2552f3bd2d5e405cc9cb101e9651ff0e07bd2a%2Fcert-dev-arp-badge.svg?alt=media)

**Product version:** API & Application Runtime Protection Paid Plans

Assesses the fundamental skills to manage your posture with API & Application Runtime Protection projects.

#### Review Study Guide

| Objective # | Description                                                                                                              | Material                                                                                                                        |
| ----------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| **1**       | **GraphQL-Based Dynamic API Ownership Assignment**                                                                       |                                                                                                                                 |
| 1.1         | Constructing and interpreting GraphQL `createPolicy` mutations for Static, Dynamic, and Regex-based policy assignments   | [API Discovery](https://docs.traceable.ai/docs/api-discovery-1)                                                                 |
| 1.2         | Configuring RE2 regular expression patterns with specific capture group indices and fallback constants                   | [API Discovery](https://docs.traceable.ai/docs/api-discovery-1)                                                                 |
| 1.3         | Managing active ownership policies using `getPolicies` queries, `updatePolicy` mutations, and `deletePolicies` mutations | [API Discovery](https://docs.traceable.ai/docs/api-discovery-1)                                                                 |
| **2**       | **Edge Cluster Deployment & Routing**                                                                                    |                                                                                                                                 |
| 2.1         | Configuring DNS vs. CDN routing models                                                                                   | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 2.2         | Edge deployment service settings (idle timeouts, keep-alive)                                                             | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 2.3         | HTTP/HTTPS Header configurations (max count, case insensitivity)                                                         | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment) / [Settings](https://docs.traceable.ai/docs/settings)         |
| 2.4         | Multi-origin distribution and backend server configurations                                                              | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 2.5         | Edge Cluster Deployment operational states (Requested, Blocked, Done)                                                    | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 2.6         | Prerequisites for Edge deployment (DNS, routing, TLS)                                                                    | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| **3**       | **High Availability & Failover Mechanics**                                                                               |                                                                                                                                 |
| 3.1         | Monitoring health using the Health Check URL                                                                             | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 3.2         | Traffic routing and behavior during localized failures                                                                   | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 3.3         | WAAP outage behaviors: Regional (partial) vs. Global (full) outages                                                      | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 3.4         | Action on global outage: Block traffic to prevent breaches                                                               | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 3.5         | Manual DNS intervention and bypass protocols                                                                             | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| 3.6         | Support escalation and status monitoring                                                                                 | [Edge Deployment](https://docs.traceable.ai/docs/edge-deployment)                                                               |
| **4**       | **Core WAAP Capabilities & Bot Protection**                                                                              |                                                                                                                                 |
| 4.1         | Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections                                          | [Web App & API Protection](https://docs.traceable.ai/docs/wap-api-protection)                                                   |
| 4.2         | Automated bot mitigation (credential stuffing, card testing, web scraping)                                               | [Bot Protection](https://docs.traceable.ai/docs/bot-protection) / [Bot Dashboard](https://docs.traceable.ai/docs/bot-dashboard) |
| 4.3         | Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS                                                  | [Runtime Protection](https://docs.traceable.ai/docs/traceable-runtime-protection)                                               |
| 4.4         | Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment                                     | [Runtime Protection](https://docs.traceable.ai/docs/traceable-runtime-protection)                                               |
| 4.5         | Identifying bot behaviors by examining aggregate patterns vs. isolated requests                                          | [Bot Protection](https://docs.traceable.ai/docs/bot-protection) / [Bot Actors](https://docs.traceable.ai/docs/bot-actors)       |
| 4.6         | Application-layer DDoS mitigation and anomaly-based rate limiting                                                        | [Web App & API Protection](https://docs.traceable.ai/docs/wap-api-protection)                                                   |
| **5**       | **Data Loss Prevention (DLP) & Zero Trust Policies**                                                                     |                                                                                                                                 |
| 5.1         | Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)                                        | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.2         | Dynamic conditions: Baseline traffic calculation for rate limiting                                                       | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.3         | Static conditions vs. dynamic conditions                                                                                 | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.4         | Data Protection: Mapping data access patterns to specific users and locations                                            | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.5         | Severity levels and enforcement actions (monitor, block, header injection)                                               | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 5.6         | Risks based on source types (anonymous VPNs, bots)                                                                       | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| **6**       | **Threat Triage, Observability & Actor Investigation**                                                                   |                                                                                                                                 |
| 6.1         | Security Events module vs. Explorer view (data scope, use cases)                                                         | [Explore Data](https://docs.traceable.ai/docs/explore-data)                                                                     |
| 6.2         | Grouping threat activities (by endpoint, rule, actor, or domain)                                                         | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 6.3         | Analyzing threat evidence (request/response logs, IP reputation, country of origin)                                      | [Custom Policies](https://docs.traceable.ai/docs/custom-policies)                                                               |
| 6.4         | Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)                                                | [Threat Scoring](https://docs.traceable.ai/docs/threat-scoring)                                                                 |
| 6.5         | Transitioning from passive monitoring to active response                                                                 | [Threat Scoring](https://docs.traceable.ai/docs/threat-scoring)                                                                 |
| 6.6         | Threat scoring based on severity and establishing a behavioral baseline                                                  | [Threat Scoring](https://docs.traceable.ai/docs/threat-scoring)                                                                 |

[**Register for Exam**](https://university-registration.harness.io/certification-exam-harness-certified-application-api-runtime-protection-developer-certification)

#### Exam Details

The Harness Application & API Runtime Protection Developer Certification exam tests your knowledge and skills of the Application & API Runtime Protection module.

**Prerequisites**

* Basic terminal skills
* Basic understanding of Harness and API protection.

**Exam Details**

Exam Duration: 90 minutes

Question Type: Multiple choice

Here is the covered domain breakdown for your 30-question developer exam, showing how the weight is evenly distributed across the 5 core objective areas:

| Covered Domain                                         | Percentage |
| ------------------------------------------------------ | ---------- |
| **Edge Cluster Deployment & Routing**                  | 20.0%      |
| **High Availability & Failover Mechanics**             | 20.0%      |
| **Core WAAP Capabilities & Bot Protection**            | 20.0%      |
| **Data Loss Prevention (DLP) & Zero Trust Policies**   | 20.0%      |
| **Threat Triage, Observability & Actor Investigation** | 20.0%      |

**Exam Objectives**

<details>

<summary>List of Objectives</summary>

The following is a detailed list of exam objectives:

| #     | Objectives                                                                           |
| ----- | ------------------------------------------------------------------------------------ |
| **1** | **Edge Cluster Deployment & Routing**                                                |
| 1.1   | Configuring DNS vs. CDN routing models                                               |
| 1.2   | Edge deployment service settings (idle timeouts, keep-alive)                         |
| 1.3   | HTTP/HTTPS Header configurations (max count, case insensitivity)                     |
| 1.4   | Multi-origin distribution and backend server configurations                          |
| 1.5   | Edge Cluster Deployment operational states (Requested, Blocked, Done)                |
| 1.6   | Prerequisites for Edge deployment (DNS, routing, TLS)                                |
| **2** | **High Availability & Failover Mechanics**                                           |
| 2.1   | Monitoring health using the Health Check URL                                         |
| 2.2   | Traffic routing and behavior during localized failures                               |
| 2.3   | WAAP outage behaviors: Regional (partial) vs. Global (full) outages                  |
| 2.4   | Action on global outage: Block traffic to prevent breaches                           |
| 2.5   | Manual DNS intervention and bypass protocols                                         |
| 2.6   | Support escalation and status monitoring                                             |
| **3** | **Core WAAP Capabilities & Bot Protection**                                          |
| 3.1   | Differentiating SQL injection (SQLi) and Cross-Site Scripting (XSS) protections      |
| 3.2   | Automated bot mitigation (credential stuffing, card testing, web scraping)           |
| 3.3   | Multi-layered security strategy: WAF, API defense, Bot mitigation, DDoS              |
| 3.4   | Out-of-band log analysis vs. inline agent-based blocking vs. managed edge deployment |
| 3.5   | Identifying bot behaviors by examining aggregate patterns vs. isolated requests      |
| 3.6   | Application-layer DDoS mitigation and anomaly-based rate limiting                    |
| **4** | **Data Loss Prevention (DLP) & Zero Trust Policies**                                 |
| 4.1   | Building a Zero-Trust DLP rule (criteria, target endpoints, authentication types)    |
| 4.2   | Dynamic conditions: Baseline traffic calculation for rate limiting                   |
| 4.3   | Static conditions vs. dynamic conditions                                             |
| 4.4   | Data Protection: Mapping data access patterns to specific users and locations        |
| 4.5   | Severity levels and enforcement actions (monitor, block, header injection)           |
| 4.6   | Risks based on source types (anonymous VPNs, bots)                                   |
| **5** | **Threat Triage, Observability & Actor Investigation**                               |
| 5.1   | Security Events module vs. Explorer view (data scope, use cases)                     |
| 5.2   | Grouping threat activities (by endpoint, rule, actor, or domain)                     |
| 5.3   | Analyzing threat evidence (request/response logs, IP reputation, country of origin)  |
| 5.4   | Managing threat actor statuses (Active, Monitored, Suspend, Deny, Snooze)            |
| 5.5   | Transitioning from passive monitoring to active response                             |
| 5.6   | Threat scoring based on severity and establishing a behavioral baseline              |

***

</details>

**Next Steps**

The Harness Application & API Runtime Protection Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

1. Create an account in Harness University
2. Register for an exam
3. Take the exam

[**Register for Exam**](https://university-registration.harness.io/certification-exam-harness-certified-application-api-runtime-protection-developer-certification)
{% endtab %}

{% tab title="For Architect" %}

### Application & API Runtime Protection - Architect (BETA COMING SOON)

![Application & API Runtime Protection - Architect (BETA COMING SOON) badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-5fce551a00a9840b259d0366b655c61dffd85aca%2Fcert-arc-arp-badge.svg?alt=media)

**Product version:** Application & API Runtime Protection Paid Plans

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

Assess key technical job functions and advanced skills in design, implementation and management of Application & API Runtime Protection.
{% endtab %}
{% endtabs %}
