API Testing for Manual QA
Learn how modern applications communicate and test REST, SOAP, GraphQL, gRPC, and WebSockets with practical tools.
All qa.cafe features are currently free. Features and test data can change before launch.
A beginner theory course for QA engineers who need clear security language, web and API risk models, testing judgment, and responsible reporting practices.
Explain information security goals, risk terms, controls, threat actors, and common attack types
Distinguish malware, social engineering, and phishing categories and connect them to product risks
Evaluate password, authentication, MFA, authorization, and access-control requirements
Explain privacy, encryption, hashing, secrets, and secure test-data handling
Recognize common web and API security risks through current OWASP awareness models
Design authorized theory-based manual security checks and interpret browser and tool evidence
Identify, assess, and report a suspected security vulnerability responsibly