Testing mode

All qa.cafe features are currently free. Features and test data can change before launch.

BeginnerSecurity

Cybersecurity Fundamentals for QA Engineers

A beginner theory course for QA engineers who need clear security language, web and API risk models, testing judgment, and responsible reporting practices.

Information securitySecurity risk analysisIdentity and access controlData protectionWeb application securityAPI securityManual security test designVulnerability reporting

What you’ll be able to do.

01

Explain information security goals, risk terms, controls, threat actors, and common attack types

02

Distinguish malware, social engineering, and phishing categories and connect them to product risks

03

Evaluate password, authentication, MFA, authorization, and access-control requirements

04

Explain privacy, encryption, hashing, secrets, and secure test-data handling

05

Recognize common web and API security risks through current OWASP awareness models

06

Design authorized theory-based manual security checks and interpret browser and tool evidence

07

Identify, assess, and report a suspected security vulnerability responsibly

9 focused modules.

36 lessons total
01Why cybersecurity matters and what this course will teach youPrepare for a defensive cybersecurity course that connects information security decisions to everyday QA work.
  1. Welcome to Cybersecurity Fundamentals for QA EngineersLesson
  2. Why information security matters to QA engineersLesson
02Security goals, language, and peopleUse precise security goals and risk terms before you classify actors, motivations, or product weaknesses.
  1. Confidentiality, integrity, and availabilityLesson
  2. Assets, threats, vulnerabilities, exploits, and riskLesson
  3. Security controls and defense in depthLesson
  4. Hackers, threat actors, and their motivationsLesson
03Cyberattacks, malware, and social engineeringRecognize common attack families and human manipulation without turning awareness material into operational attack guidance.
  1. Types of cyberattacks and how attack paths developLesson
  2. Malware and its typesLesson
  3. Social engineering techniques and warning signsLesson
  4. Phishing and its typesLesson
04Passwords, identity, and access decisionsSeparate password quality, identity proof, authentication factors, and authorization decisions across an account lifecycle.
  1. Password security and account riskLesson
  2. Authentication and authentication factorsLesson
  3. Multi-factor authentication and phishing resistanceLesson
  4. Authorization, access control, and least privilegeLesson
05Data security, privacy, encryption, and hashingProtect data according to its purpose and lifecycle, then distinguish encryption, hashing, secrets, logs, and backups.
  1. Data security, privacy, and the data lifecycleLesson
  2. Encryption at rest and in transitLesson
  3. Hashing, integrity, and password storageLesson
  4. Secrets, test data, logs, and backupsLesson
06Web application security and common vulnerabilitiesRebuild the web request model, then connect common vulnerability families to trust boundaries and observable QA evidence.
  1. Web application components and trust boundariesLesson
  2. Input validation, injection, and cross-site scriptingLesson
  3. Sessions, cookies, and cross-site request forgeryLesson
  4. Common web vulnerabilities beyond injectionLesson
  5. Security misconfiguration, errors, and loggingLesson
07OWASP and API security foundationsUse current OWASP awareness models while tracing API identities, objects, properties, resources, and business flows.
  1. OWASP Top 10:2025 overviewLesson
  2. API security basics and trust boundariesLesson
  3. API authentication, authorization, and object accessLesson
  4. OWASP API Security Top 10:2023 overviewLesson
08Security testing theory for manual QADesign authorized security questions, interpret static browser and tool evidence, and work safely with specialists and delivery teams.
  1. Security requirements and risk-based test designLesson
  2. Manual security testing through case analysisLesson
  3. Browser DevTools as a source of security evidenceLesson
  4. Basic security testing tool categories and their limitsLesson
  5. Security best practices and authorized testing boundariesLesson
09Vulnerability reporting and course synthesisTurn careful observations into bounded findings, decision-ready reports, coordinated triage, and a complete Northstar security review.
  1. Identifying and validating a suspected security vulnerabilityLesson
  2. Reporting, triaging, and disclosing vulnerabilitiesLesson
  3. Capstone: review Northstar Tickets security risksLesson
  4. Review your cybersecurity outcomes and choose the next practiceLesson