Kursen har inget datum. Ring vår kursbokning 077 186 10 37 för information om en privat utbildning.
Översikt
| Kurskod | RL358SE | Leveranstyp | Classroom
(Hands-on labs) |
|---|---|---|---|
| Kurslängd | 2.0 dagar | Kurstyp | |
| Listpris | Set by Partner |
In this course, you learn how to use IBM Rational AppScan Enterprise. The course combines both class lectures and hands-on lab work so that you can learn how to use the product to test for web application security issues. You learn to use best practices in the context of real-world deployments. You gain hands-on experience using Rational AppScan Enterprise on demonstration web applications.
Målgrupp
This basic course is for security auditors, security team managers, quality assurance practitioners, and web application developers who need to understand web application vulnerability testing reports, run web application security scans on web applications, and administer Rational AppScan Enterprise.
The audience might also include web developers, managers, or team leaders who are responsible for interacting with testers or who need to ensure that the tools are being implemented fully and appropriately.
Förkunskaper
Mål
- Describe the capabilities of Rational AppScan Enterprise
- Explain the potential risks of conducting an automated security scan
- Work with dashboards, jobs, folders, reports, and alerts
- Explain the differences between manual and automatic exploration
- Configure, run, and optimize scans
- Use scan logs and identify messages, export a scan log, and troubleshoot scans
- Describe the process of analyzing scan results and using issue management
- Explain the architecture of Rational AppScan Enterprise
- Administer users, groups, and manage access control
- Create scan templates and test policies
- Describe best practices for generating management reports
- Explain the major tasks and factors involved in a Rational AppScan Enterprise deployment
Nyckelområden
- Rational AppScan Enterprise overview
- Before you begin scanning
- Reports overview
- Managing folders, jobs, report packs, and dashboards
- Configuring a basic scan
- Automatic versus manual exploration
- Complex login and session management
- Reviewing explore results
- Advanced configuration options
- Security tests, reports, and concepts
- Scan logs, phases, and error messages
- Security Issue reports
- Issue management
- Users, groups and managing access control
- Creating scan templates
- Test policies
- Management reporting
- Deployment planning