For the complete documentation index, see llms.txt. This page is also available as Markdown.

Traceable by Harness

Learn Traceable by Harness through Harness University

Capture, correlate and analyze all app and API-related activity over time, across your entire app and API ecosystem.

Go to Harness University for the full catalogue of courses and certifications.

Self-Paced Training

Free self-paced courses that you can consume on your own time.

Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

Traceable by Harness - Developer

Traceable by Harness - Developer badge

Product version: Traceable by Harness Paid Plans

Assesses the fundamental skills to manage your posture with Traceable by Harness projects.

Review Study Guide

Topic
Material

1. API Discovery & Classification

1.1 API Protocol Recognition (REST, SOAP, gRPC, GraphQL, WebSocket)

1.2 Endpoint Classification (internal vs external) & Third-Party Insights

1.3 Shadow, Orphan, and Undocumented Endpoints Identification

2. API Documentation, Conformance & Governance

2.1 Conformance Analysis (shadow/orphan detection, parameter mismatches)

2.2 API Documentation Formats & Downloads (OpenAPI, JSON/YAML, WSDL)

2.3 Parameters, Retention Windows, and Conformance Issue Actions

3. API Risk, Issues & Posture Management

3.1 Risk Score Factors (live issues, sensitive data, posture events)

3.2 Issue Lifecycle (severity, evidence, filtering, ownership)

3.3 Impact of Issues on Endpoint Risk & Governance

4. Endpoint Traces, Spans & Explorer

4.1 Trace vs Span Concepts & Telemetry Querying Models

4.2 Explorer Usage (filters, group-by, metrics, exact vs relative ranges)

4.3 Query Retention, Filtering Interactions, and Real-Time Detection

5. AST (API Security Testing)

5.1 AST Inputs & File Support (specs, Postman, JSON/YAML)

5.2 Dynamic vs Static AST, Scanning Scope & Mutations/Assertions

5.3 CI/CD Integration, Scheduling & Correlation with Live Traffic

6. Agents, Deployment & Telemetry

6.1 Platform Agent vs Runtime Agent Responsibilities

6.2 Deployment Configuration (tokens, CA trust, connectivity)

6.3 Telemetry Collection, Environment Separation & Troubleshooting

7. Bot Protection

7.1 Bot Detection (behavior, fingerprinting, monitored threats)

7.2 CAPTCHA Logic, Metrics, Good-Bot Identification

7.3 Bot Dashboard, Endpoint Behavior Analysis & Monitor Mode

8. Fraud Protection

8.1 Credential Stuffing, Fake Signups & Account Takeover Indicators

8.2 Fraud Actor Tracking (scores, sessions, continuity, fingerprints)

8.3 Endpoint Abuse Patterns & Data Exfiltration Signals

9. Protection Policies & Zero-Trust Rules

9.1 Policy Types (rate limiting, data protection, bot mitigation)

9.2 Zero-Trust Conditions (session/user behavior, IP, user agents)

9.3 Simulate/Preview Modes & Custom Plugin/Test Development

Register for Exam

Exam Details

The Traceable by Harness (API & Application Discovery) Developer Certification exam tests your knowledge and skills of the API & Application Discovery (Traceable by Harness) module.

Prerequisites

  • Basic terminal skills

  • Basic understanding of Harness and API security.

Exam Details

Exam Duration: 90 minutes

Question Type: Multiple choice

Covered Domain
Percentage

API Discovery & Classification

9.7%

API Documentation, Conformance & Governance

5.4%

API Risk, Issues & Posture Management

12.9%

Endpoint Traces, Spans & Explorer

10.8%

AST (API Security Testing)

11.8%

Agents, Deployment & Telemetry

7.5%

Bot Protection

15.1%

Fraud Protection

17.2%

Protection Policies & Zero-Trust Rules

9.7%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objectives

1

API Discovery & Classification

1.1

API Protocol Recognition (REST, SOAP, gRPC, GraphQL, WebSocket)

1.2

Endpoint Classification (internal vs external) & Third-Party Insights

1.3

Shadow, Orphan, and Undocumented Endpoints Identification

2

API Documentation, Conformance & Governance

2.1

Conformance Analysis (shadow/orphan detection, parameter mismatches)

2.2

API Documentation Formats & Downloads (OpenAPI, JSON/YAML, WSDL)

2.3

Parameters, Retention Windows, and Conformance Issue Actions

3

API Risk, Issues & Posture Management

3.1

Risk Score Factors (live issues, sensitive data, posture events)

3.2

Issue Lifecycle (severity, evidence, filtering, ownership)

3.3

Impact of Issues on Endpoint Risk & Governance

4

Endpoint Traces, Spans & Explorer

4.1

Trace vs Span Concepts & Telemetry Querying Models

4.2

Explorer Usage (filters, group-by, metrics, exact vs relative ranges)

4.3

Query Retention, Filtering Interactions, and Real-Time Detection

5

AST (API Security Testing)

5.1

AST Inputs & File Support (specs, Postman, JSON/YAML)

5.2

Dynamic vs Static AST, Scanning Scope & Mutations/Assertions

5.3

CI/CD Integration, Scheduling & Correlation with Live Traffic

6

Agents, Deployment & Telemetry

6.1

Platform Agent vs Runtime Agent Responsibilities

6.2

Deployment Configuration (tokens, CA trust, connectivity)

6.3

Telemetry Collection, Environment Separation & Troubleshooting

7

Bot Protection

7.1

Bot Detection (behavior, fingerprinting, monitored threats)

7.2

CAPTCHA Logic, Metrics, Good-Bot Identification

7.3

Bot Dashboard, Endpoint Behavior Analysis & Monitor Mode

8

Fraud Protection

8.1

Credential Stuffing, Fake Signups & Account Takeover Indicators

8.2

Fraud Actor Tracking (scores, sessions, continuity, fingerprints)

8.3

Endpoint Abuse Patterns & Data Exfiltration Signals

9

Protection Policies & Zero-Trust Rules

9.1

Policy Types (rate limiting, data protection, bot mitigation)

9.2

Zero-Trust Conditions (session/user behavior, IP, user agents)

9.3

Simulate/Preview Modes & Custom Plugin/Test Development

Next Steps

The Traceable by Harness Developer (API & Application Discovery) exam can start immediately after registering. Please allow up to 90 mins for the exam.

  1. Create an account in Harness University

  2. Register for an exam

  3. Take the exam

Register for Exam

Traceable by Harness - Administrator (BETA COMING SOON)

Traceable by Harness - Administrator (BETA COMING SOON) badge

Product version: Traceable by Harness Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assesses the fundamental skills to deploy and maintain Traceable by Harness projects and the overall Harness Platform.

Traceable by Harness - Architect (BETA COMING SOON)

Traceable by Harness - Architect (BETA COMING SOON) badge

Product version: Traceable by Harness Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assess key technical job functions and advanced skills in design, implementation and management of Traceable by Harness.

Last updated

Was this helpful?