C and C++ have no single package manager, and that absence is the fact this course is built around. You will cover the actual landscape of system package managers, vendored source trees, git submodules and the newer dependency managers such as Conan and vcpkg, and what security property each one gives up compared to a real lockfile. It covers static versus dynamic linking and what each tells you about what is actually running, the build system itself as an execution surface, the absence of a central advisory feed tied to a single package identity, Application Binary Interface (ABI) compatibility risk that has no equivalent in higher level ecosystems, and the inventory problem that is usually the first real task a security team faces in a large legacy codebase. It closes with overriding a vulnerable vendored dependency, upgrading one that is several major versions behind, and what a security policy across many ecosystems has to concede when one of those ecosystems has none of the infrastructure the others take for granted. Companion to the published Java, JavaScript, Python and Go courses in the same series.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.