Skip to main content

Security Fundamentals and Threat Modeling

Learn the security fundamentals every engineer needs: the CIA triad, OWASP Top 10, encryption and TLS, and threat modeling with STRIDE.

~3.5 hours
9 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Security Is Every Engineer's Job

A small payments startup in Pune shipped a feature on a Thursday. One API endpoint returned a user's profile by ID: GET /api/users/1042.

Understanding the CIA Triad and Access Control

Before you can protect a system, you need words for what "protected" means.

Understanding the OWASP Top 10

The OWASP Top 10 is the security industry's most widely used awareness document.

Preventing Injection and Keeping Code Separate from Data

Injection has been near the top of every OWASP list for two decades because the underlying mistake is so easy to make: the application takes input...

Choosing Between Hashing and Encryption

"Encrypt it" is the advice people reach for whenever data feels sensitive, and half the time encryption is the wrong tool.

Securing Connections with TLS, Certificates, and PKI

Every time you see the padlock in a browser, hashing and both kinds of encryption are working together.

Skills You'll Master

SECURITYOWASPTHREAT-MODELINGSTRIDETLS

Curriculum Index9 topics

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

  • Platform Engineer

  • Cloud Engineer

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

No. This module is for any engineer who builds or runs software. It teaches the shared vocabulary (CIA, OWASP, STRIDE) and the few ideas you use every day, so you can reason about risk and talk to security teams without memorising a certification syllabus.

No, and OWASP says so directly. It is an awareness document of the most common risk categories, not a complete test. Use it to learn the usual ways apps get attacked, then rely on threat modeling and testing to find what is specific to your system.

Authentication proves who you are, like showing an ID at a door. Authorization decides what you are allowed to do once you are inside, like which rooms your key card opens. Most access-control bugs come from getting authorization wrong, not authentication.

Not to use it safely. You need to know when to use hashing versus encryption, when to use symmetric versus asymmetric, and never to invent your own scheme. The maths matters for people who design algorithms; your job is to use well-tested libraries correctly.