A developer-focused course on session hijacking and token theft as a distinct attack path that bypasses login and multi-factor authentication entirely by stealing an already-valid session. You will learn what a session token actually represents, how tokens are stolen through cross-site scripting, adversary in the middle relay phishing kits, and lower-tech paths such as logs and embedded URLs, how to defend token storage and transport with cookie flags and encryption, how session lifetime, binding, and refresh token rotation limit the damage a stolen token can do, and how to detect and respond to a suspected hijack in progress.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.