Course Description
With global cybersecurity markets projected to grow exponentially, the demand for professionals with strong security testing skills is at an all-time high. The CSST certification covers far more than penetration testing, ensuring learners can evaluate multiple security threats and vulnerabilities using diverse testing approaches.
The program provides participants with hands-on insights into attacker mentality, simulating real-world actions on test applications in controlled environments, and understanding how malicious actors attempt to exploit and cover their tracks.
By mastering risk assessment, auditing, and policy analysis, professionals will gain the skills necessary to strengthen organizational security and improve testing practices.
Exam Information
Exam Pattern: 50 Multiple Choice Questions; pass mark: 80% (40/50 correct).
Exam Duration: 60 Minutes (1 hour).
Exam Format: Non-proctored, can be taken anytime and anywhere within an 8-month validity period.
Includes a voucher code with 2 attempts.
If both attempts are unsuccessful, a new voucher must be purchased (grants 2 more attempts).
Kindly Note: The voucher is not valid for a second attempt if the candidate passes on the first attempt.
Certification Validity: Lifetime
Course Outline
Module Set 1
Security Risks
Asset Identification
Assessing Risk Analysis Effectiveness
Information Security Policies and Procedures
Analysis of Information Security Policies and Procedures
Security Auditing and Its Role in Security Testing
Security Risk Assessment
Security Triad
Introduction to Security Testing
Module Set 2
Purpose of Security Testing
The Organizational Context
Security Testing Objectives
Information Assurance vs. Security Testing
Scope and Coverage of Security Testing Objectives
Analysis of Security Approaches
Analysis of Failures in Security Test Approaches
Stakeholder Identification
Improving the Security Testing Practice
Target Audience
Software testers seeking to expand their knowledge of security testing
Security testers aiming for advanced certification to validate expertise
Security administrators responsible for evaluating organizational defenses
IT professionals and learners interested in building a foundation in security testing