A deep, strictly defensive treatment of Server Side Request Forgery (SSRF): basic versus blind variants, internal network and cloud metadata targets described generically, and allowlist bypass and permissive parsing library classes, mapped to CWE-918. Every example is framed around a vulnerable feature, a webhook validator and an avatar fetch by URL, and its fix, never around an attacker's request. You will learn how the category is actually found through manual review, Dynamic Application Security Testing and out-of-band detection, how it is fixed and prevented including network-layer egress control, and where Safeguard's scoped dynamic testing honestly intersects with it.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.