Hello All,
I have started preparing and have been working through the previous exams to get a sense of how the questions are structured. Before I go further, I would like to ask a few short questions:
- Is the entire lecture within the scope of the exam, or are there topics that are explicitly not examined?
- Are the practical topics from the exercises (SSTI, file upload vulnerabilities, XSS, clickjacking, CSRF, API security testing) examined in a practical form as well, or mainly conceptually?
- Are the older exams still representative of the current format?
If you can guide us towards these questions it would be much of a help.