This course explains how software developers and testers can determine if their web applications are vulnerable to A05:2021 Security Misconfiguration, as defined by the Open Web Application Security Project (OWASP).
Learning Objectives
On successful completion of this course, learners should have the knowledge and skills required to:
- Identify vulnerabilities caused by security misconfiguration
- Develop and implement a testing strategy to evaluate the attack surface and to identify misconfiguration vulnerabilities
- Conduct manual and automated tests to identify common misconfiguration vulnerabilities, targeting operating systems, web servers, and databases
Framework Connections
Specialty Areas
- Test and Evaluation
- Systems Analysis
- Vulnerability Assessment and Management
Feedback
If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.