A practitioner course on two related session riding techniques that exploit a browser's own trust behavior rather than any application injection flaw: cross-site request forgery (CSRF), which forges a state-changing request using a victim's already authenticated session, and clickjacking, which deceives a victim into clicking a real interface element they cannot actually see. You will learn the synchronizer token pattern and the SameSite cookie attribute as CSRF defenses, the X-Frame-Options header and the Content-Security-Policy frame-ancestors directive as clickjacking defenses, how the two techniques can be chained together against a partially defended application, and how to design, review, and operationally maintain state-changing endpoints against both.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.