Awarded for completing Deception Technology and Honeytokens and passing its exam, demonstrating the ability to explain how deception assets detect a post-compromise attacker, distinguish honeytokens from heavier decoys such as honeypots and honeynets, apply containment discipline to decoy systems, place deception assets using a realistic attacker progression map, measure a deception programme's value, and integrate deception alerts into an existing incident response process.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.