The syllabus follows the API Security Engineering exam domains, with the most time spent on the heaviest-weighted areas and your weakest topics.
Authentication and OAuth/OIDC protocol security
Object, property and function authorization
Gateway, Kubernetes and zero-trust policy
Resource controls, logging and privacy
Key rotation, mTLS/DPoP and security testing
Object, property and function authorization testing
Input validation, SSRF and unsafe API consumption
Resource and sensitive-flow abuse prevention
Inventory, versioning, configuration and Kubernetes controls
Logging, privacy, incidents and regression
Domain weights come from the published exam outline used in PrepKloud projects. We recheck the latest official Security Engineering objectives with you in the first session.