Unit rationale, description and aim
Modern organisations require cybersecurity professionals who can evaluate the security of systems, applications and networks through authorised offensive security testing. Ethical hacking and penetration testing provide structured methods for identifying vulnerabilities before they can be exploited by malicious actors. This unit complements foundational, defensive and governance-focused units in the course by developing advanced capability in reconnaissance, vulnerability assessment, controlled exploitation, and professional reporting within legal and ethical boundaries.
This unit examines the principles and practice of ethical hacking and penetration testing in controlled environments. Students apply structured penetration testing methodologies to scope engagements, gather intelligence, identify vulnerabilities, validate exploitability and communicate findings. The unit also explores web, mobile and application security testing, the use of contemporary tools such as Kali Linux and Metasploit, and emerging issues such as vulnerabilities introduced by AI-generated code and AI-assisted offensive techniques.
The aim of this unit is to develop students’ capacity to plan and conduct authorised penetration testing activities, evaluate security weaknesses, and communicate technically sound and ethically responsible findings and recommendations.
Campus offering
No unit offerings are currently available for this unit.Learning outcomes
To successfully complete this unit you will be able to demonstrate you have achieved the learning outcomes (LO) detailed in the below table.
Each outcome is informed by a number of graduate capabilities (GC) to ensure your work in this, and every unit, is part of a larger goal of graduating from ACU with the attributes of insight, empathy, imagination and impact.
Explore the graduate capabilities.
Apply structured penetration testing methodologies...
Learning Outcome 01
Evaluate vulnerabilities through authorised exploi...
Learning Outcome 02
Produce professional penetration testing reports ...
Learning Outcome 03
Critically evaluate legal, ethical and professiona...
Learning Outcome 04
Content
Topics will include:
Penetration testing foundations
Authorisation, scope, rules of engagement, penetration testing methodologies, and professional standards.
Reconnaissance and vulnerability assessment
Open-source intelligence (OSINT), scanning, enumeration, attack-surface analysis, and vulnerability identification and validation.
Controlled exploitation and post-exploitation
Exploitation techniques including SQL injection, buffer overflow and race condition vulnerabilities; privilege escalation, lateral movement, persistence risks, and safe lab-based validation.
Web, application and enterprise security testing
OWASP-aligned testing, common web vulnerabilities, exploitation workflows, remediation strategies, and enterprise-focused topics such as Active Directory attacks and misconfiguration exploitation.
AI-related offensive security issues
AI-assisted attack techniques, vulnerabilities introduced by AI-generated code, and risks in AI-supported testing workflows.
Reporting, remediation and professional practice
Writing penetration testing reports, communicating findings to stakeholders, responsible disclosure, and legal, ethical and professional considerations in offensive security practice.
Assessment strategy and rationale
The assessment strategy is designed to progressively develop students’ capability from planning and analysis to applied testing and critical professional judgement. Assessment 1 requires students to scope an authorised engagement and conduct reconnaissance and vulnerability assessment, developing foundational capability in penetration testing methodology and evidence gathering. Assessment 2 then requires students to perform controlled exploitation and analyse findings in a laboratory environment, demonstrating technical competence and interpretive skill. Assessment 3 requires students to critically evaluate a complex offensive security scenario involving legal, ethical, reporting and AI-related issues, and justify an appropriate professional response. Together, the assessments provide a coherent progression from analysis to application to advanced evaluation, and support achievement of all learning outcomes. To pass this unit, students must demonstrate competence in all learning outcomes and achieve an aggregate mark of at least 50%.
Overview of assessments
Task 1: Penetration testing plan and reconnaissan...
Task 1:Penetration testing plan and reconnaissance report
Students prepare a scoped penetration testing plan for a realistic target environment and conduct authorised reconnaissance, enumeration and vulnerability assessment. They document assumptions, scope boundaries, tools, evidence and initial findings, and justify the proposed testing approach.
Submission Type: Individual
Assessment Method: Written
Artefact: report (1000 words)
20%
Task 2: Applied penetration testing report Stud...
Task 2: Applied penetration testing report
Students conduct controlled exploitation activities in a sandboxed environment using approved tools and techniques. They analyse the evidence collected, validate vulnerabilities, assess impact, and produce a professional report with remediation recommendations.
Submission Type: Individual
Assessment Method: Report+Presentation
Artefact: 1000 words plus technical appendix/screenshots+ Live / Recorded with face-overlay Presentation (5 minutes) + Online Viva
40%
Task 3: Critical professional case analysisStude...
Task 3: Critical professional case analysis
Students critically evaluate a complex offensive security scenario involving issues such as authorisation, disclosure, AI-assisted exploit development. They justify an ethically and professionally defensible course of action for both technical and organisational stakeholders.
Submission Type: Individual
Assessment Method: Written Report and Presentation
Artefact: 1000 words plus technical appendix/screenshots+ Live / Recorded with face-overlay Presentation (5 minutes) + Online Viva
40%
Learning and teaching strategy and rationale
This unit is delivered fully online, primarily in an asynchronous mode, through recorded lectures, guided learning resources, virtual lab activities, case-based learning and discussion forums. Students engage in authorised, sandboxed offensive security exercises designed to develop methodological rigour, technical capability and professional judgement. Learning activities support AQF Level 9 expectations by requiring students to analyse complex security scenarios, justify testing decisions, interpret technical evidence and communicate findings responsibly. To further support student learning, up to three optional synchronous online workshops will be offered during the unit for assessment consultation and clarification.
Students should plan to commit approximately 150 hours to this unit over the semester, including participation in learning activities, independent study, readings and assessment preparation.