Quick Note
- Bundle offer: eCourseware + iLab Access + Exam Voucher.
- Training: Self-Paced Online (Official EC-Council Training).
- Course Version: Latest available version in the EC-Council catalog.
- Access Delivery: Once your order is processed, your login credentials will be sent directly from the EC-Council team to your registered email within 2–3 business days. Don't forget to check your spam folder just in case.
Course Description
The Certified Application Security Engineer (CASE) focuses on secure application software development processes. It is a hands-on, comprehensive application security course that will help you create a secure application software.
This course encompasses security activities involved in all phases of the Secure Software Development Lifecycle (SDLC): planning, creating, testing, and deploying an application.
Unlike other application security trainings, CASE goes beyond just the guidelines on secure coding practices to include secure requirement gathering, robust application design, and handling security issues in post development phases of application development.
Audience
.NET / Java Developers with a minimum of 2 years of experience and individuals who want to become application security engineers/analysts/testers.
Individuals involved in the role of developing, testing, managing, or protecting applications
Prerequisites
To be eligible to challenge the CASE Exam, the candidate must either:
Complete the official EC-Council CASE training through EC-Council online official course.
Be an ECSP (.NET/ Java) member in good standing.
Have a minimum of 2 years working experience in InfoSec/ Software domain.
Have any other industry equivalent certifications such as GSSP .NET/Java.
Exam Details
Exam Title: Certified Application Security Engineer
Number of Questions: 50
Test Duration: 2 Hours
Test Format: Multiple Choice
Availability: EC-Council Exam Portal
Certified Application Security Engineer Java (CASE Java) (Bundle offer)
EASTER SALES 40% OFF
CASE training program include secure requirement gathering, robust application design, and handling security issues in post development phases of application development.
You will learn:
- In-depth understanding of secure SDLC and secure SDLC models
- Knowledge of OWASP Top 10, threat modelling, SAST and DAST
- Capturing security requirements of an application in development
- Defining, maintaining, and enforcing application security best practices
- Performing manual and automated code review of application
- Conducting application security testing for web applications to assess the vulnerabilities
- Driving development of a holistic application security program
- Rating the severity of defects and publishing comprehensive reports, detailing associated risks
and mitigations - Application security scanning technologies such as AppScan, Fortify, WebInspect, static
application security testing (SAST), dynamic application security testing (DAST), single signon,
and encryption - Following secure coding standards that are based on industry-accepted best practices such as
OWASP Guide, or CERT Secure Coding to address common coding vulnerabilities - Creating a software source code review process that is a part of the development cycles (SDLC,
Agile, CI/CD)

