Course details

This instructor-led class provides students with a thorough grounding in Microsoft .NET security implementation and general development security best practices. This course will prepare a student to take the Implementing Security for Applications exam.

Target Audience

This course is intended for experienced, professional application developers, including those employed by software companies or working on corporate development teams.

Objectives

  • Explain the basic concept of application security.
  • Implement platform security best practices.
  • Implement coding security best practices.
  • Implement security using CLR and application domains.
  • Implement role-based security by using the Microsoft .NET Framework.
  • Implement CAS to secure applications.
  • Implement cryptography in .NET.
  • Improve the Security of remote applications built on the .NET Framework.
  • Improve the Security of ASP.NET applications.
  • Manage and configure security policies using Framework tools.
  • Test application security.
  • Deploy applications in a manner that minimizes security risks.

Course Outline

  • Overview of Application Security
  • The Importance of Application Security
  • Application Security Best Practices
  • Implementing Platform Security Best Practices
  • Security Best Practices for COM+, IIS, and SQL Server 2000
  • Using ACLs and DACLs
  • Using Windows Least-Privilege Accounts
  • Using Audit Trails
  • Implementing Platform Cryptography
  • Implementing Data Protection
  • Implementing Coding Security Best Practices
  • Validating Application Input
  • Evaluating Canonicalization Issues
  • Using Security Exceptions
  • Using .NET Framework Security Features
  • Implementing CLR Security Mechanism
  • Implementing Security Using Application Domains
  • Implementing Role-based Security
  • Basics of Role-Based Security
  • Role-Based Security with Principal and Identity Objects
  • Role-Based Security with Permission Objects
  • Implementing Code-Access Security
  • Overview of Code-Access Security
  • Performing Basic Security Operations
  • Performing Imperative Security Operations
  • Performing Declarative Security Operations
  • Adding Permission Requests
  • Implementing Cryptography in .NET
  • Implementing Symmetric Cryptography
  • Implementing Asymmetric Cryptography
  • Securing ASP.NET Applications
  • Implementing Authentication in ASP.NET Applications
  • Implementing Authorization in ASP.NET Applications
  • Implementing Impersonation in ASP.NET Applications
  • Securing Web Files and Folders
  • Securing Remote .NET Applications
  • Introducing .NET Application Security
  • Implementing Authentication and Authorization in .NET Remoting Applications
  • Introducing Web Service Security
  • Implementing WS Security
  • Configuring .NET Security
  • Managing Security Policies Using Mscorcfg.msc
  • Managing Security Policy Levels Using Mscorcfg.msc
  • Implementing Security Testing
  • Overview of Security Testing
  • Creating a Security Test Plan
  • Performing Security Testing
  • Deploying Applications with Security
  • Deploying .NET Applications with Security Settings
  • Deploying .NET Applications with Publisher Identity and Code Integrity
Updated on 08 November, 2015

About Equitrain

EquiTrain –a pision of Equinox International- equips organizations with IT skills that are the lifeblood of modern corporate life, as Theyll as the professional expertise required for ensuring productivity and to remain competitive now and tomorrow.

At EquiTrain, They tailor end-to-end training solutions that incorporate both IT and business consultancy to the specific needs of each inpidual customer. They can equip yTheir IT professionals with all they need to quickly maximize yTheir new technology investments as Theyll as pushing forward absolute beginners on their road to IT proficiency.

They offer a broad range of IT and Management training cTheirses and certifications from top technology vendors with a choice of on-site or offsite, public or closed and local or abroad training. Their portfolio of cTheirses is supplemented by Their strategic training alliance with world's leading providers of learning solutions.

See all Equitrain courses
Are you from Equitrain ? Claim your course!
Courses you can instantly connect with... Do an online course on Networking and Security starting now. See all courses

Is this the right course for you?

Rate this page

Didn't find what you were looking for ?

or