A practitioner's grounding in cross-site scripting as untrusted input rendered without adequate encoding, letting an attacker's script run in another user's browser under the victim application's own trust. You will learn the three classic categories, reflected, stored and DOM-based, context-aware output encoding as the primary defense, Content Security Policy as a complementary defense-in-depth layer, the specific dangers of trusting a client-side framework's automatic encoding without understanding its escape hatches, session cookie protections as a mitigation for consequence rather than a fix for the cause, and how to test for cross-site scripting responsibly as part of a security review.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.