Skip to Content

EC-Council Certified Secure Programmer (ECSP) .NET

This training is offered to study the software life cycle, that is to say the design, implementation, and deployment of these applications.

This training will therefore enable developers to identify security flaws and implement countermeasures throughout the software life cycle in order to generally improve the quality of products and applications. The ECSP.Net training presents the essential foundations required by all application developers and by all development organizations to produce applications that exhibit better stability with less risk to consumer security. This training is intentionally designed with numerous labs spread over the 3 days of training, providing participants with real hands-on experience of new techniques and strategies in secure programming.

0.000 DT 0.000 DT
  • Familiarize yourself with .NET application security and ASP.NET security architecture, and help you understand the security needs of applications as well as common security threats to the .NET framework.

  • Discuss security attacks on the .NET framework and explain the secure software development life cycle.

  • Help you understand the common threats facing .NET assemblies and familiarize yourself with the operational processes of the stack.

  • Discuss the necessity of input validation, different approaches to input validation, common input validation attacks, validation control vulnerabilities, and best practices for input validation.

  • Familiarize yourself with authorization and authentication processes as well as common threats related to authorization and authentication.

  • Discuss the different security principles for session management tokens, common threats related to session management, ASP.NET session management techniques, and various session attacks.

  • Cover the importance of cryptography in .NET, the different types of cryptographic attacks in .NET, and the various .NET cryptography namespaces.

  • Explain symmetric and asymmetric encryption, hashing concepts, digital certificates, digital signatures, and XML.

  • Describe the principles of secure error handling, the different levels of exception management, and the various .NET logging tools.

  • Examine file management concepts, security issues related to file management, path traversal attacks on file processing, and defense techniques against these attacks.

  • Code: ECSP.Net
  • Duration: 3 days
  • Schedule: 9:00 AM – 4:00 PM
  • Location: Tunis

You must be well-versed in the .NET programming language.

The ECSP certification is intended for programmers tasked with designing and creating secure Windows/Web applications using the .NET Framework. It is aimed at developers with .NET development skills.

  • Introduction to .NET Application Security

  • Security of .NET Structures

  • Data Validation and Output Encoding

  • Authentication and Authorization .NET

  • Secure Session and State Management

  • Cryptography .NET

  • Error Management, Audits, and Logs .NET

  • Secure File Management .NET

  • Configuration Management .NET and Secure Coding Review

Certification and Exam

  • Number of Questions : 50

  • Passing Score : 70 %

  • Test Duration : 2 hours

  • Test Format : Multiple Choice

  • Exam Organization : EC-Council Exam Center

  • Exam Code : 312-93