Application Security Testing - STO
Learn Security Testing Orchestration through Harness University
Seamlessly integrate security scanners and orchestrate tests anywhere across your build pipelines. Enable developers to rapidly remediate vulnerabilities through intelligent prioritization and deduplication.
Go to Harness University for the full catalogue of courses and certifications.
Self-Paced Training
Free self-paced courses that you can consume on your own time.
Instructor-Led Training
Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.
Certifications
Test and validate your knowledge of Harness by becoming a Harness Certified Expert.
Security Testing Orchestration - Developer
Product version: Harness STO Free Plans
Assesses the fundamental skills to deploy your applications with STO projects.
Review Study Guide
1. Introduction to Harness Security Testing Orchestration
Explain the importance of security testing in modern software development.
Describe the common issues in current security testing practices, including manual and standalone scanning, slow identification of vulnerabilities, siloed visibility, and inconsistent governance.
2. Setting up the Environment
Install and configure Harness Security Testing Orchestration on a local development environment.
Connect Harness Security Testing Orchestration to version control systems (e.g., Git) and CI/CD pipelines, emphasizing the integration aspect to address manual and standalone scanning.
3. Creating Test Plans
Create a basic security test plan using Harness Security Testing Orchestration.
Define test scenarios, including target applications, endpoints, and test inputs, with a focus on automation to eliminate delays.
4. Test Automation
Implement basic security tests, such as OWASP Top Ten vulnerabilities scanning, and automate them within CI/CD pipelines to address the issue of delayed identification of vulnerabilities.
Integrate third-party security testing tools into Harness Security Testing Orchestration to expand automated scanning capabilities.
5. Test Execution and Reporting
Execute security tests within a CI/CD pipeline as gate checks, ensuring that vulnerabilities are identified before release.
Analyze and interpret security test results and generate reports, promoting visibility into vulnerabilities throughout the development process.
6. Integration and Extensibility
Customize security testing workflows in Harness Security Testing Orchestration to align with specific release processes, addressing inconsistent governance.
Integrate additional security testing tools or plugins seamlessly to consolidate scanning efforts.
7. Security Best Practices
Apply security best practices to code and infrastructure within the CI/CD pipeline, ensuring that scans are integrated into the release process.
Implement security testing as an integral part of the software development lifecycle, avoiding siloed visibility.
8. Compliance and Regulations
Understand and adhere to relevant compliance standards (e.g., GDPR, HIPAA) in security testing.
Ensure that security testing processes align with regulatory requirements, emphasizing the importance of integration and governance.
9. Troubleshooting and Debugging
Identify and resolve common issues and errors in security testing, including problems related to integration and automation.
Debug integration problems between Harness Security Testing Orchestration and other tools to maintain a smooth CI/CD pipeline.
10. Performance Optimization
Optimize security testing processes for efficiency and speed within the CI/CD pipeline.
Implement caching and parallelization strategies for security tests to address the issue of speed and delays in vulnerability identification.
Exam Details
The Security Testing Orchestration(STO) Developer exam tests your knowledge and skills of the Harness Security Testing Orchestration module.
Prerequisites
Basic terminal skills
Basic understanding of on-premise or cloud architecture
Exam Details
Knowledge Exam
90 minutes
Introduction to Harness Security Testing Orchestration
10%
Setting up the Environment
10%
Creating Test Plans
10%
Test Automation
15%
Test Execution and Reporting
15%
Integration and Extensibility
10%
Security Best Practices
10%
Compliance and Regulations
5%
Troubleshooting and Debugging
10%
Performance Optimization
5%
Exam Objectives
Next Steps
The Security Testing Orchestration Developer exam can start immediately after registering. Please allow up to 90 mins to complete the knowledge exam.
Create an account in Harness University
Review the Study Guide above.
Register for an exam.
Take the exam.
Security Testing Orchestration - Administrator
Product version: Harness STO Paid Plans
Assesses the fundamental skills to deploy and maintain STO Engineering projects and the overall Harness Platform. This exam builds upon the STO Developer Certification.
Review Study Guide
1. Harness Security Testing Overview
Understand the core principles and concepts of Harness Security Testing Orchestration.
Explain the importance of security testing in the software development lifecycle.
Differentiate between various types of security testing (e.g., static analysis, dynamic analysis, penetration testing) and their relevance in Harness.
2. Setting Up Harness Security Testing Environment
Install and configure Harness Security Testing Orchestration in a lab or testing environment.
Integrate Harness with popular security testing tools and platforms.
Create and manage user accounts and permissions for Harness Security Testing.
3. Creating Security Testing Pipelines
Define security testing workflows within Harness, including pre-test and post-test actions.
Configure pipeline triggers and conditions for automated security testing.
Establish notification and alerting mechanisms for test results.
4. Managing Test Artifacts
Upload and manage security test artifacts, including source code, binaries, and test data.
Implement version control and artifact tagging strategies within Harness.
Optimize storage and resource utilization for test artifacts.
5. Automated Security Test Execution
Execute automated security tests using various testing tools and frameworks through Harness.
Schedule and orchestrate recurring security test runs.
Monitor and analyze test execution results and log data.
6. Security Test Reporting and Analysis
Generate comprehensive security test reports and dashboards.
Analyze test results to identify vulnerabilities and security issues.
Provide recommendations for remediation based on test findings.
7. Integration with CI/CD
Integrate Harness Security Testing into continuous integration and continuous deployment (CI/CD) pipelines.
Ensure seamless automation and feedback loops between development and security teams.
Implement version control and artifact tagging strategies within Harness.
8. Security Testing Best Practices
Demonstrate an understanding of industry best practices in security testing.
Apply secure coding principles and techniques to reduce vulnerabilities.
Stay updated with the latest security threats and vulnerabilities relevant to software development.
9. Security Compliance and Governance
Implement security compliance policies and standards within Harness Security Testing.
Ensure regulatory and industry-specific compliance (e.g., GDPR, HIPAA) in security testing processes.
Perform security risk assessments and provide recommendations for risk mitigation.
Exam Details
The Security Testing Orchestration Administrator exam tests your knowledge and skills of the Harness Security Testing Orchestration module.
Prerequisites
Intermediate terminal skills
Basic understanding of on-premise or cloud architecture
This exam builds upon the Security Testing Orchestration Developer Exam
Exam Details
Knowledge Exam
90 minutes
Hands On Exam
120 minutes
1. Harness Security Testing Overview
16%
2. Setting Up Harness Security Testing Environment
15%
3. Creating Security Testing Pipelines
14%
4. Managing Test Artifacts
11%
5. Automated Security Test Execution
13%
6. Security Test Reporting and Analysis
10%
7. Integration with CI/CD
9%
8. Security Testing Best Practices
6%
9. Security Compliance and Governance
6%
Exam Objectives
Next Steps
The Security Testing Orchestration Administrator exam can start immediately after registering. Please allow 90 mins for the knowledge exam and approximately 120 minutes for the hands on exam.
Create an account in Harness University
Register for an exam. There is a $50 fee for the exam
Review the instructions for the Hands On Exam
Take the exams
There will be a knowledge and hands on portion.
Last updated
Was this helpful?