BBuddyAI Learn
Cybersecurity · Beginner → Expert

🔐 Application Security and Secure Coding

Build secure applications using threat modeling, input handling, identity, access control, cryptography, session security, APIs, dependency safety, testing and secure deployment.

Course roadmap

Pass each module exam to unlock the next module.

Module 1 · Beginner

Secure Development Lifecycle and Threat Modeling

Locked
Module 2 · Beginner

Input Validation, Output Encoding and Injection Defense

Locked
Module 3 · Beginner

Authentication Design and Credential Security

Locked
Module 4 · Beginner

Authorization and Access Control Models

Locked
Module 5 · Intermediate

Session Management, Cookies and CSRF Protection

Locked
Module 6 · Intermediate

Browser Security, XSS, CSP and Clickjacking Defense

Locked
Module 7 · Intermediate

SQL Injection and Safe Database Access

Locked
Module 8 · Intermediate

API Security, Tokens and Object-Level Authorization

Locked
Module 9 · Advanced

Cryptography, TLS and Secret Management

Locked
Module 10 · Advanced

File Uploads, Deserialization and Dangerous Inputs

Locked
Module 11 · Advanced

Dependency and Software Supply Chain Security

Locked
Module 12 · Advanced

Secure Logging, Errors and Privacy

Locked
Module 13 · Expert

Security Testing: SAST, DAST and Manual Review

Locked
Module 14 · Expert

Security Headers, Configuration and Deployment Hardening

Locked
Module 15 · Expert

Vulnerability Management and Remediation

Locked
Module 16 · Expert

Expert Capstone: Security Review of a Production Application

Locked
Certification gate

Final course exam

Pass mark: 80%. Time limit: 360 minutes. All module exams must be passed first.

Locked until modules are passed