<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="36189" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/opentext-2-7739" lastchanged="2025-07-29T12:18:45+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Dynamic Application Security Testing (DAST) Essentials</title><productcode>2-7739</productcode><vendorcode>MF</vendorcode><vendorname>OpenText</vendorname><fullproductcode>MF-2-7739</fullproductcode><version>24.4</version><objective>&lt;p&gt;On completion of this course, participants should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use Fortify DAST WebInspect to run, view, and respond to security incidents leveraging Fortify technologies to solve customer business problems based on the defined scenarios.&lt;/li&gt;&lt;li&gt;Successfully complete the lessons below in an environment that acts as a production environment.&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To be successful in this course, you should have the following prerequisites or knowledge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Familiarity with WebInspect for at least one month&lt;/li&gt;&lt;li&gt;Basic programming skills&lt;/li&gt;&lt;li&gt;Ability to read HTTP(S) requests and responses&lt;/li&gt;&lt;li&gt;Basic understanding of web technologies, REST API, and command-line&lt;/li&gt;&lt;li&gt;Proficiency in navigating Windows desktop, browser, and file system&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is intended for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Security Champions&lt;/li&gt;&lt;li&gt;Application Testers&lt;/li&gt;&lt;li&gt;Administrators responsible for utilizing WebInspect within their environment&lt;/li&gt;&lt;li&gt;AppSec Users taking their first steps toward leveraging the power of Fortify DAST WebInspect&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;h5&gt;Learning Scenario:&lt;/h5&gt;&lt;p&gt;The course will follow your journey as a Security AppSec Tester. Your management has decided to purchase the Fortify DAST WebInspect solution to address the growing risks in application security and to empower users to effectively identify vulnerabilities in web applications.&lt;/p&gt;
&lt;p&gt;As the security champion, you will become proficient with the Fortify DAST WebInspect technology in a lab environment that closely mirrors a production setting.&lt;/p&gt;
&lt;h5&gt;Chapter 01: DAST methodology, basic scans, scan results, macros, and reports&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain how DAST crawls and audits an application&lt;/li&gt;&lt;li&gt;Learn the DAST licensing&lt;/li&gt;&lt;li&gt;Run a Smart Update&lt;/li&gt;&lt;li&gt;Learn the key concepts of DAST&lt;/li&gt;&lt;li&gt;Recognize the DAST User Interfaces (UI)&lt;/li&gt;&lt;li&gt;Discover where to find DAST help&lt;/li&gt;&lt;li&gt;Run a Guided scan&lt;/li&gt;&lt;li&gt;Create a Login macro&lt;/li&gt;&lt;li&gt;Run a scan using your Login macro&lt;/li&gt;&lt;li&gt;Generate DAST reports&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 02: Additional DAST Scanning Methods and Macros&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Create a Workflow macro while running a Workflow scan&lt;/li&gt;&lt;li&gt;Comprehend DAST Two-Factor (2F) authentication&lt;/li&gt;&lt;li&gt;Run a Manual scan&lt;/li&gt;&lt;li&gt;Run a List-Driven scan&lt;/li&gt;&lt;li&gt;Manage and schedule scans in DAST&lt;/li&gt;&lt;li&gt;Compare scan results&lt;/li&gt;&lt;li&gt;Use command-line to run scans&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 03: API Scans, Postman Collections, Security Tools, and Scan Policy&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Run REST API scans&lt;/li&gt;&lt;li&gt;Generate vulnerability report based on the scans&lt;/li&gt;&lt;li&gt;Run a SOAP Web Services scan&lt;/li&gt;&lt;li&gt;Run advanced API Postman Collection scans&lt;/li&gt;&lt;li&gt;Utilize the DAST security tools&lt;/li&gt;&lt;/ul&gt;</contents><objective_plain>On completion of this course, participants should be able to:


- Use Fortify DAST WebInspect to run, view, and respond to security incidents leveraging Fortify technologies to solve customer business problems based on the defined scenarios.
- Successfully complete the lessons below in an environment that acts as a production environment.</objective_plain><essentials_plain>To be successful in this course, you should have the following prerequisites or knowledge:


- Familiarity with WebInspect for at least one month
- Basic programming skills
- Ability to read HTTP(S) requests and responses
- Basic understanding of web technologies, REST API, and command-line
- Proficiency in navigating Windows desktop, browser, and file system</essentials_plain><audience_plain>This course is intended for:


- Security Champions
- Application Testers
- Administrators responsible for utilizing WebInspect within their environment
- AppSec Users taking their first steps toward leveraging the power of Fortify DAST WebInspect</audience_plain><contents_plain>Learning Scenario:

The course will follow your journey as a Security AppSec Tester. Your management has decided to purchase the Fortify DAST WebInspect solution to address the growing risks in application security and to empower users to effectively identify vulnerabilities in web applications.

As the security champion, you will become proficient with the Fortify DAST WebInspect technology in a lab environment that closely mirrors a production setting.

Chapter 01: DAST methodology, basic scans, scan results, macros, and reports


- Explain how DAST crawls and audits an application
- Learn the DAST licensing
- Run a Smart Update
- Learn the key concepts of DAST
- Recognize the DAST User Interfaces (UI)
- Discover where to find DAST help
- Run a Guided scan
- Create a Login macro
- Run a scan using your Login macro
- Generate DAST reports
Chapter 02: Additional DAST Scanning Methods and Macros


- Create a Workflow macro while running a Workflow scan
- Comprehend DAST Two-Factor (2F) authentication
- Run a Manual scan
- Run a List-Driven scan
- Manage and schedule scans in DAST
- Compare scan results
- Use command-line to run scans
Chapter 03: API Scans, Postman Collections, Security Tools, and Scan Policy


- Run REST API scans
- Generate vulnerability report based on the scans
- Run a SOAP Web Services scan
- Run advanced API Postman Collection scans
- Utilize the DAST security tools</contents_plain><duration unit="d" days="3">3 jours</duration><pricelist><price country="DE" currency="EUR">2400.00</price></pricelist><miles/></course>