Main question
How can defenders reduce web-application risk without breaking legitimate user and business workflows?
This module treats web security as an evidence and engineering problem. Students identify what the application should do, where trust changes, which controls should apply, what the logs prove, how to fix weaknesses narrowly, and how to validate both security and normal use.
Safety boundary
Fictional, inert, authorized, and defensive
All requests, pages, inputs, cookies, tokens, sessions, accounts, logs, devices, servers, databases, users, and organizations are fictional. Students analyze supplied safe evidence and defensive patterns. They do not test real websites, create harmful payloads, bypass access controls, access accounts, run exploit tools, or collect private data.