National data — wages and growth are not published by state for this view.
Certification
GIAC Web Application Penetration Tester (GWAPT)
GIAC
Median earnings
—
Cost
—
Duration
—
Completion
—
The GIAC Web Application Penetration Tester (GWAPT) certification validates a practitioner's ability to better secure organizations through penetration testing and a thorough understanding of web application security issues. GWAPT certification holders have demonstrated knowledge of web application exploits and penetration testing methodology.
Understand Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilitiesUnderstand techniques used to conduct discovery, exploration, and investigation of web sites and web application features including port scanning, identifying services and configurations, spidering, application flow charting, and session analysisUnderstand the process and mechanisms used to secure web applications by authentication, enumerate users, and bypass and exploit weak authenticationUse tools and techniques to audit and identify flaws in the design or implementation in the configuration of a web siteUnderstand the technologies, programming languages, and structures used in web applications including HTTP, HTTPS, and AJAX in the context of security and vulnerabilitiesUnderstand how web applications manage client sessions, track user activity, use SSL/TLS, and the attacks against session stateUse techniques to audit and test web applications using SQL injection attacks and identify SQL injection vulnerabilitiesUse tools and techniques to perform web application security testing including proxies, fuzzing, scripting, and attacking application logic