What is the CCPE-AW certification?
The Check Point CCPE Advanced Web Hacking (CCPE-AW, exam 156-408) is an advanced web application penetration testing course focusing on server-side vulnerabilities that modern scanners miss. It covers SSO attacks, JWT/SAML/OAuth exploitation, XXE, deserialization RCE, advanced SQLi, SSRF, and cloud-hosted application attacks.
What are the prerequisites for CCPE-AW?
Candidates must have a strong understanding of the OWASP Top 10 vulnerabilities before attending. CCPE-W (156-403) is the recommended prerequisite. This is not a beginner course β it builds directly on foundational web security knowledge.
How does CCPE-AW differ from CCPE-W?
CCPE-W covers entry-level web security testing (OWASP Top 10, SQLi basics, auth attacks). CCPE-AW advances into server-side flaws that automated scanners miss β JWT/SAML/OAuth exploitation, deserialization RCE, second-order SQLi, advanced XXE, and cloud-hosted app attacks.
What tools are used in CCPE-AW?
The course uses Burp Suite Pro as the primary tool, alongside SQLMap for advanced injection, and various custom exploitation scripts for deserialization, OOB data extraction, and cloud enumeration. All tools are demonstrated from configuration to exploitation.
How many questions are on the 156-408 exam?
The exam contains approximately 60 multiple-choice questions with a 90-minute time limit. The passing score is 70%, delivered via Pearson VUE either online proctored or at an authorised test centre.
What does Zetlan Technologies offer for CCPE-AW preparation?
Zetlan provides expert-led Advanced Web Hacking training covering all seven modules β from SSO attacks through GraphQL and HTTP desync β with live online sessions, advanced web app lab access, and comprehensive study materials.