Aller au contenu principal
Authentication, encryption, network security, application security, and secure system design.

Security

Authentication, encryption, network security, application security, and secure system design.

Niveau 8

Security

Authentication, encryption, network security, application security, and secure system design.

0/8 terminés 8 Disponible

Authentication & Authorization Models

Available

Understand user identity and access control — password auth, JWT, OAuth2, SAML, RBAC, and modern auth protocols.

Difficulty:
★★★★★
2/5 · Elementary
Sessions JWT OAuth2 SSO +2
2–3 hours
Requires: HTTP/HTTPS & REST APIs
Start Learning

Identity & Access Management Patterns

Available

RBAC vs ABAC, SCIM, OAuth scopes, OIDC flows, JWT validation pitfalls, token replay — the implementation patterns behind the auth models topic.

Difficulty:
★★★★★
4/5 · Advanced
RBAC vs ABAC vs ACL OAuth 2.0 scopes and grant types OpenID Connect (OIDC) and ID tokens JWT structure, validation, and pitfalls +1
3 hours
Requires: Authentication & Authorization Models, Distributed Systems Fundamentals
Start Learning

Cryptography & Encryption Basics

Available

Cover the essential cryptographic primitives — symmetric and asymmetric encryption, hashing, digital signatures, and TLS.

Difficulty:
★★★★★
3/5 · Intermediate
Symmetric Encryption Asymmetric Encryption Hashing Digital Signatures +1
3–4 hours
Start Learning

Network Security & Firewalls

Available

Deepen network security knowledge — firewall rules, security groups, network ACLs, WAFs, DDoS protection, and zero-trust architectures.

Difficulty:
★★★★★
3/5 · Intermediate
Security Groups NACLs WAF DDoS Mitigation +1
2–3 hours
Requires: Network Security Fundamentals
Start Learning

Secure System Design Principles

Available

Apply security-by-design principles — threat modeling, least privilege, defense in depth, secrets management, and security reviews.

Difficulty:
★★★★★
4/5 · Advanced
Threat Modeling Least Privilege Defense in Depth Secrets Management +1
3–4 hours
Requires: Authentication & Authorization Models, Cryptography & Encryption Basics
Start Learning

Threat Modeling (STRIDE, DREAD, Attack Trees)

Available

Threat modeling as a practiced skill — STRIDE per element, DREAD for ranking, attack trees for adversary reasoning, and the data-flow diagram as the working surface.

Difficulty:
★★★★★
4/5 · Advanced
Threat modeling as a process, not a document STRIDE per element (Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation) DREAD ranking (Damage, Reproducibility, Exploitability, Affected users, Discoverability) Attack trees for adversary reasoning +1
3 hours
Requires: Secure System Design Principles, Authentication & Authorization Models
Start Learning

Application Security (OWASP & Secure Coding)

Available

Defense at the source — the OWASP Top 10, input validation, injection, XSS, CSRF, insecure deserialization, and the secure-coding habits that prevent vulnerabilities before they ship.

Difficulty:
★★★★★
3/5 · Intermediate
OWASP Top 10 Injection XSS CSRF +2
4–5 hours
Requires: Authentication & Authorization Models, HTTP/HTTPS & REST APIs
Start Learning

Supply Chain Security

Available

The software supply chain is now an attack surface — SBOMs, signed artifacts, Sigstore/Cosign, dependency vetting, and SLSA as the maturity ladder.

Difficulty:
★★★★★
4/5 · Advanced
SBOM (Software Bill of Materials) Signed artifacts and Sigstore / Cosign SLSA framework levels Dependency vetting (transitive, pinned, locked) +1
3 hours
Requires: Application Security (OWASP & Secure Coding), CI/CD Pipelines
Start Learning