← All 186 courses
SEC-501 Security

AI Security: Defending LLM Applications

Secure the new attack surface: prompt injection (direct and indirect), jailbreak patterns, data exfiltration through model outputs, insecure tool invocation and RAG poisoning — each demonstrated against a deliberately vulnerable LLM app, then systematically defended with layered guardrails and measured red-team-style regression tests.

B5Advanced
5modules
35skill atoms
2role journeys
Curriculum

What this course covers.

5 modules, 35 named skill atoms. Expand any module to see them.

1LLM Threat Model7 skill atoms
OWASP-LLM-style risk maptrust boundariesuntrusted content treated as instructionsprompt, retrieval, tool & output trust zonespath from user input to privileged actionmodel & weight supply chain riskinsecure output handling
2Prompt Injection Defense7 skill atoms
direct/indirect vectorsisolation patternsindirect injection through retrieved documentsinstruction and data separationprivilege separation between planning and executionprovenance tagging of untrusted contentconfirmation gates for irreversible actions
3Data Exfiltration Controls7 skill atoms
output filteringsecret hygiene in contextrendered link & image exfiltration channelsegress allow-listing for model outputPII redaction before context assemblyper-tenant retrieval isolationprompt logging & retention policy
4RAG & Tool Hardening7 skill atoms
corpus integritytool permissioningsandboxingingestion source vetting & poisoning detectiondocument ACL enforcement at retrieval timetool argument schema validationdeny-by-default tool allow-lists
5Guardrail Engineering7 skill atoms
layered defensesbypass testingregression suiteinput & output classifiers with measured precisionlimits of system prompt hardeningusage anomaly detection & rate limitingevaluation harness wired into CI
Where it fits

SEC-501 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

AI Security Engineer

Practitioner stage
SEC-101SEC-501SEC-303

AppSec Engineer

Capstone stage
SEC-306SEC-501journey complete

Roles this course serves

The capability ladder

This course is authored to band B5.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-501 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free