Awarded for completing Session Hijacking and Token Theft Defense and passing its exam, demonstrating the ability to distinguish session hijacking from credential theft and account takeover, explain how cross-site scripting and adversary in the middle relay attacks steal a valid token, configure cookie and transport protections correctly, apply session lifetime and binding as defense in depth, and run a correct incident response for a suspected session hijack.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.