Testing mode Features and test data can change before launch.
BeginnerSecurity

Cybersecurity Fundamentals for QA Engineers

A beginner course for QA engineers with complete offline cases, practical security explanations, and a release-review capstone. No live security testing is required.

Information securityRisk analysisIdentity and access controlData protectionWeb application securityAPI securityManual security test designVulnerability reporting

What you’ll be able to do.

01

Explain information security goals, risk terms, controls, threat actors, and common attack types

02

Distinguish malware, social engineering, and phishing categories and connect them to product risks

03

Evaluate password, authentication, MFA, authorization, and access-control requirements

04

Explain privacy, encryption, hashing, secrets, and secure test-data handling

05

Recognize common web and API security risks using the OWASP web 2025 and API 2023 awareness models

06

Design authorized manual security checks and interpret supplied browser, request, configuration, and tool evidence

07

Identify, assess, and report a suspected security vulnerability responsibly

8 focused modules.

36 lessons total
01Security goals and product riskConnect security goals, threats, controls, and possible harm to Northstar Tickets.
  1. ↳Welcome to Cybersecurity Fundamentals for QA EngineersLesson
  2. ↳Why information security matters to QA engineersLesson
  3. ↳Confidentiality, integrity, and availabilityLesson
  4. ↳Assets, threats, vulnerabilities, exploits, and riskLesson
  5. ↳Security controls and defense in depthLesson
  6. ↳Hackers, threat actors, and their motivationsLesson
02Cyberattacks, malware, and social engineeringRecognize common attack families and human manipulation without turning awareness material into operational attack guidance.
  1. ↳Types of cyberattacks and how attack paths developLesson
  2. ↳Malware and its typesLesson
  3. ↳Social engineering techniques and warning signsLesson
  4. ↳Phishing and its typesLesson
03Passwords, identity, and access decisionsSeparate password quality, identity proof, authentication factors, and authorization decisions across an account lifecycle.
  1. ↳Password security and account riskLesson
  2. ↳Authentication and authentication factorsLesson
  3. ↳Multi-factor authentication and phishing resistanceLesson
  4. ↳Authorization, access control, and least privilegeLesson
04Data security, privacy, encryption, and hashingProtect data according to its purpose and lifecycle, then distinguish encryption, hashing, secrets, logs, and backups.
  1. ↳Data security, privacy, and the data lifecycleLesson
  2. ↳Encryption at rest and in transitLesson
  3. ↳Hashing, integrity, and password storageLesson
  4. ↳Secrets, test data, logs, and backupsLesson
05Web application security and common vulnerabilitiesRebuild the web request model, then connect common vulnerability families to trust boundaries and observable QA evidence.
  1. ↳Web application components and trust boundariesLesson
  2. ↳Input validation, injection, and cross-site scriptingLesson
  3. ↳Sessions, cookies, and cross-site request forgeryLesson
  4. ↳Common web vulnerabilities beyond injectionLesson
  5. ↳Security misconfiguration, errors, and loggingLesson
06OWASP and API security foundationsUse current OWASP awareness models while tracing API identities, objects, properties, resources, and business flows.
  1. ↳OWASP Top 10:2025 overviewLesson
  2. ↳API security basics and trust boundariesLesson
  3. ↳API authentication, authorization, and object accessLesson
  4. ↳OWASP API Security Top 10:2023 overviewLesson
07Security testing theory for manual QADesign authorized security questions, interpret static browser and tool evidence, and work safely with specialists and delivery teams.
  1. ↳Security requirements and risk-based test designLesson
  2. ↳Manual security testing through case analysisLesson
  3. ↳Browser DevTools as a source of security evidenceLesson
  4. ↳Basic security testing tool categories and their limitsLesson
  5. ↳Security best practices and authorized testing boundariesLesson
08Vulnerability reporting and course synthesisTurn careful observations into bounded findings, decision-ready reports, coordinated triage, and a complete Northstar security review.
  1. ↳Identifying and validating a suspected security vulnerabilityLesson
  2. ↳Reporting, triaging, and disclosing vulnerabilitiesLesson
  3. ↳Capstone: review Northstar Tickets security risksLesson
  4. ↳Review your cybersecurity outcomes and choose the next practiceLesson