End of 2024 20% Discount Promotion
Only 2 days
Classroom
14/01/2025 (Tuesday)
Overview
This accelerated EC Council Certified DevSecOps Engineer E|CDE certification is is a hand-on instructor led comprehensive DevSecOps course that helps professionals build the essential skills to design, develop and maintain secure applications and infrastructure.
The E|CDE is a perfect blend of theoretical and practical knowledge of DevSecOps in your on-premises and cloud native (AWS and Azure) environment.
The course focuses on application DevSecOps and provides insights into infrastructure DevSecOps and helps DevSecOps Engineers develop and enhance their knowledge and skills in securing the application in all the stages of DevOps.
In just 2 days, you’ll learn to understand DevSecOps security bottlenecks and discover how the culture, philosophy, practices, and tools of DevSecOps can enhance collaboration and communication across development and operations teams. You’ll also learn how to:
- Integrate Eclipse and GitHub with Jenkins to build applications.
- Integrate threat modeling tools like Threat Dragon, ThreatModeler and Threatspec; manage security requirements with Jira and Confluence; and use Jenkins to create a secure CI/CD pipline.
- Integrate runtime application self-protection tools like Hdiv, Sqreen, and Dynatrace that protect applications duriing runtime with fewr false positives and remediate known vulnerabilities.
- Implement tools like the Jfrog IDE plugin and the Codacy platform.
- Implement automated tools to identify security misconfigurations that could expose sensitive information and result in attacks.
- Audit code pushes, pipelines and compliance using logging and monitoring tools like Sumo Logic, Datadog, Splunk, the ELK stack and Nagios.
- Integrate compliance-as-code tools like Cloud Custodian and the DevSec framework to ensure that organisational regulatory or compliance requirements are met without hindering production.
- Integrate tools and practices to build continuous feedback into the DevSecOps pipline using Jenkins and Microsoft Teams email notifications.
- Understand the DevSecOps toolchain and how to include security controls in automated DevOps pipelines.
- Align security practices like security requirement gathering, threatmodelling, and secure code reviews with development workflows.
- Understand and implement continuos security testing with static, dynamic, and interactive application security testing and SCA tools (e.g. Snyk, SonarQube, StackHawk, Checkmarx SAST, Debricked, WhiteSource Bolt).
- Integrate SonarLint with the Eclipse and Visual Studion Code IDEs.
- Integrate automated security testing into a CI/CD pipline using Amazon CloudWatch; Amazon Elastic Container Registry; and AWS CodeCommit, CodeBuild, CodePipeline, Lambada, and Security Hub.
- Perform continuos vulnerability scans on data and product builds using automated tools like Nessus, SonarCloud, Amazon Macie and Probely.
- Use AWS and Azure tools to secure applications.
- Understand the concept of infrastructure as code and provision and configure infrastructure using tools like Ansible, Puppet and Chef.
- Use automated monitoring and alerting tools (e.g. Splunk, Azure, Monitor, Nagios) and create a real-time alert and control system.
- Scan and secure infrastructure using container and image scanners (Trivy and Qualys) and infrastructure security scanners (Bridgecrew and Chekov).
- Integrate alerting tools like Opsgenie with log management and monitoring tools to enhance operations performance and security.
At the end of this course, you’ll sit the EC Council exam, and achieve your EC Council Certified DevSecOps Engineer E|CDE certification.
Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.
Audience
This course is ideal for:
- C|ASE - certified professionals
- Application security professionals
- DevOps Engineers
- IT security professionals
- Cybersecurity engineers and analysts
- Software engineers and testers
- Anyone with prior knowledge of application security who wants to build a career in DevSecOps
Curriculum
- Module 1: Understanding DevOps Culture
- Module 2: Introduction to DevSecOps
- Module 3: DevSecOps Pipeline-Plan Stage
- Module 4: DevSecOps Pipeline-Code Stage
- Module 5: DevSecOps Pipeline - Build and Test Stage
- Module 6: DevSecOps Pipeline - Realease and Deploy Stage
- Module 7: DevSecOps Pipeline - Operate and Monitor Stage
Exam Track
At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:
EC Council Certified DevSecOps Engineer E|CDE exam
- Duration: 4 Hours
- Format: multiple-choice questions
- Number of questions: 100 questions
- Passing score: 70%
The E|CDE is a lab-intensive certification where students will spend 70% of their total class time performing the labs. The labs are designed in such a way that they simulate a real-time DevSecOps pipeline. They also demonstrate the essential tools, technologies and procedures widely used across the DevSecOps professional community. Which will provide you with rich hands-on experience in integrating and automating security practices in the DevOps Lifecycle.
Prerequisites
Before attending this accelerated course, you should have an understanding of application security concepts.
What's Included
Your accelerated course includes:
- Accommodation *
- Meals, unlimited snacks, beverages, tea and coffee *
- On-site exams **
- Exam vouchers **
- Practice tests **
- Certification Guarantee ***
- Courseware
- Up-to 12 hours of instructor-led training each day
- 24-hour lab access
- Digital courseware **
* For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
** Some exceptions apply. Please refer to the Exam Track or speak with our experts.
*** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.
Benefits
Seven reasons why you should sit your course with Firebrand Training
- Two options of training. Choose between residential classroom-based, or online courses
- You'll be certified fast. With us, you’ll be trained in record time
- Our course is all-inclusive. A one-off fee covers all course materials, exams**, accommodation* and meals*. No hidden extras.
- Pass the first time or train again for free. This is our guarantee. We’re confident you’ll pass your course the first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
- You’ll learn more. A day with a traditional training provider generally runs from 9 am – 5 pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day of quality learning time, with your instructor
- You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
- You’ll be studying with the best. We’ve been named in the Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified over 135,000 professionals
*For residential training only. Doesn't apply for online courses
**Some exceptions apply. Please refer to the Exam Track or speak with our experts
Think you are ready for the course? Take a FREE practice test to assess your knowledge! Free Practice Test