You get a total of 48 hours to attempt your certification exam. This includes completing all challenges, in-depth questions, and a DevSecOps project. The timer will only begin counting down once you sign in to the assessments page and start the exam, so take your time and prepare as much as you need!
You can attempt the certification exam 2 times. We believe in second chances!
No, there are no restrictions on how long you spend on any particular lab or hands-on environment, as long as it’s within the 48-hour time limit.
The certification exam is broken up into 3 parts: Challenges, In-Depth Questions, and the Project. Challenges will be auto-evaluated by our systems, but the questions and project will be carefully evaluated by our in-house team of security experts.
For the Challenges, you’ll be asked to solve simple and complex problems within a real-world environment, from finding vulnerabilities in a piece of code, to running automated scans within a pipeline. The whole challenge will take place within our lab environment.
Once you’ve fixed the problem, you can enter a validation code and the system will check your solution. If you’ve solved the issue, you’ll be given a unique completion code which you can submit to complete your challenge!
You’ll be given a set of questions that will test not only your technical knowledge of security and software supply chains, but also help us understand how you’ll go about solving real-world problems in a DevSecOps pipeline.
Our team of DevSecOps experts will evaluate your answers based on how coherent and detailed they are.
The project is perhaps the most involved part of your certification exam. We’ll lay out a full-fledged security scenario where you’ll need to build your own DevSecOps solution from scratch.
You’ll need to record a video explaining how you approached the project and what steps you took to complete it. You can also upload any files and artifacts related to the project for our viewing. Our team will carefully evaluate each and every aspect of your submission to see how well you’ve constructed your solution.
Before you take the exam, you need to complete the required curriculum. This covers the exact skills you’ll be tested on, including SAST, SCA, DAST, supply chain security, and secure CI/CD automation. You’ll learn how to plug these tools into real pipelines and catch real threats before they hit production.
Download the Curriculum Guidelines
This curriculum is included with your certification.
Learning Path + Certification
Includes the full DevSecOps learning path (~41 hours of hands-on training), the required curriculum, and the certification exam. This option gives you the most complete preparation and qualifies you for up to 40 CPE credits.
If you already have the experience and just want to take the exam:
Exam Only
Includes access to the required curriculum and two exam attempts.
Want the deeper dive?
You can also add in the DevSecOps learning path, a more comprehensive and hands-on version of the same material. You’ll get extra labs, challenges, and advanced exercises across:
Static and dynamic testing in CI/CD
Building custom SAST rules
Secrets management at scale
Pipeline integration with tools like GitHub Actions, GitLab CI, Gaia, and more
It’s not required but if you want to actually be ready for the exam (and not just guess your way through), we recommend it. You’ll have 12 months to complete the certification, but once you begin the exam, you’ll need to finish it within 48 hours.
You get two attempts. Once you start an attempt, you have 48 hours to complete it. The exam includes:
Practical challenges
Questions to check your understanding
A hands-on project you record and submit using our video portal
An evaluator will review your submission within 48 hours. If you pass, your certificate will be issued within 24 hours.
DevOps Engineers
Application Security Engineers
Application Security Analysts
Security Engineers
IT Security Analysts
Introduction to SAST
SAST for source code
SAST for configuration management, Infrastructure-as-Code
Building custom SAST rules with AST enabled tools
Practical Exercises in SAST for different scenarios
Generating and validating Software Bill of Materials
Understanding Source Code Analysis
Security implications of Open-Source Software
Using Secure base images for containerization
Trusted sources for security vulnerabilities
Hands-on SCA practices
Identifying secrets in code repositories and environment
Understanding Key Management tool
Advanced encryption techniques
Leveraging Dynamic Secrets Management
Case studies on managing secrets in the pipeline
Introduction to DAST
Learning to use popular tools like OWASP ZAP and Nuclei
Leveraging API based scanning with ZAP
Crafting custom template-based scans using Nuclei
Bringing DAST to the DevOps pipeline
Explore a plethora of CI/CD tools like GitLab CI and GitHub Actions
Leverage data flow automation tools like Robot Framework and Gaia
Setup secure defaults in repositories using CodeQL, Dependabot, etc.
Demonstration of the completed pipeline
Comprehensive project covering all aspects of the curriculum
Real-world scenario-based project
Application of learned skills to design, implement, and secure a pipeline
Peer review and professional evaluation
Download the Curriculum Guidelines
Reminder
The DevSecOps learning path is included with the certification and covers all required topics in depth. It takes about 41 hours to complete, which also determines how many CPE credits you can claim. An exam-only option is available if you already have the necessary experience.
How CPE credits work (ISC2 Handbook)
Note:
You can choose to bundle the DevSecOps learning path with your certification at the time of purchase. It’s not required, but it’s the best way to prepare with hands-on labs and guided exercises
Yes, you must complete the required curriculum before you are eligible to take the certification exam.
The curriculum is the set of topics and skills you must complete to qualify for the exam. The DevSecOps learning path is an optional, more comprehensive training program that covers all curriculum topics in greater depth with additional practical exercises.
No, the learning path is not required. However, it is recommended because it offers detailed coverage, hands-on practice for all curriculum topics, and gives you the best shot at success.
You have one year from your enrollment date to complete the curriculum and attempt the exam.
You are allowed two exam attempts within your one-year enrollment period.
The exam is online and consists of practical challenges, comprehension questions, and a hands-on project. You have 48 hours to complete the exam once you start.
An evaluator will review your submission within 48 hours. If you pass, your certificate will be emailed to you within 24 hours after the evaluation.
Yes, if you complete the full DevSecOps learning path, you can claim up to 40 CPE credits under ISC2’s Continuing Professional Education (CPE) guidelines. Detailed instructions for claiming credits will be provided.
You can email us at help@appsecengineer.com for any support or questions.