Awarded for completing Path Traversal and Command Injection and passing its exam, demonstrating the ability to explain how path traversal and command injection arise, apply canonicalization and base directory verification, prefer safe alternatives to shell invocation and the structured argument list pattern, apply sandboxing and least-privilege process execution as defense-in-depth, and review code for both vulnerability classes together.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.