A hardening course built on a single discipline: removing or disabling anything not actually needed for a system to do its job, since a feature, port, service, or permission that is not used cannot be secured in any meaningful sense, only removed. It explains why attack surface tends to grow rather than shrink over a system's lifetime, meaning capability accumulates by default and a deliberate reduction effort is what reverses the drift, and itdraws a firm line against secure-defaults-in-templates, cross-referenced rather than repeated, since that course scopes specifically to service scaffolding and template propagation while this one covers the general hardening philosophy. The course works through an inventory-first method for finding out what is actually running, listening, installed, or granted before deciding what to remove, across four concrete categories: open network ports and listening services, installed but unused software packages, overly broad permission grants, and enabled but unused product features. It develops a safe removal process of disable first, monitor for breakage, then delete, cross-referenced to change-management-as-a-security-control rather than repeated, since a hardening change still carries the same risk as any other change. It confronts the honest tension between attack surface reduction and operational flexibility, since a broadly permissioned, feature-rich system is often easier to run day to day even though it is less secure, and closes on measuring reduction progress as an ongoing metric, cross-referenced to security-metrics-and-kpi-design, and the relationship to external-attack-surface-management, cross-referenced rather than repeated, since that course discovers the surface from outside while this one covers the internal decision to reduce it once discovered. No real reduction case study is named; every scenario is explicitly hypothetical.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.