| HTTP Security Headers o  Content-Security-Policy (CSP)o  Strict-Transport-Security Header (HSTS)
 o  X-Content-Type-Options
 o  X-Frame-Options
 o  Referrer-Policy
 Introduction to Web Application Security o  Vulnerability Stacko  Defense in depth
 Web Application Penetration Testing Methodology o  OWASP (Open Web Application Security Project)o  OSSTMM (Open Source Security Testing Methodology Manual)
 o  PTF (Penetration Testing Framework)
 o  ISSAF (Information Systems Security Assessment Framework)
 o  PCI DSS (Payment Card Industry Data Security Standard)
 o  Types of Web Penetration Testing o  Internal Penetration Testingo  External Penetration Testing
 o  Web Application Penetration Testing Tools o  Zed Attack Proxy (ZAP)o  Wfuzz
 o  Wapiti
 o  W3af
 o  SQLMap
 Web Application Penetration Testing Checklist o  Penetration Testing Certificationso  OSWE (Offensive Security Web Expert)
 o  GWAPT (GIAC Web Application Penetration Tester)
 o  CWAPT (Certified Web App Penetration Tester)
 o  eWPT (elearnSecurity Web Application Penetration Tester)
 |