Unit rationale, description and aim

Modern organisations require cybersecurity professionals who can evaluate the security of systems, applications and networks through authorised offensive security testing. Ethical hacking and penetration testing provide structured methods for identifying vulnerabilities before they can be exploited by malicious actors. This unit complements foundational, defensive and governance-focused units in the course by developing advanced capability in reconnaissance, vulnerability assessment, controlled exploitation, and professional reporting within legal and ethical boundaries.

This unit examines the principles and practice of ethical hacking and penetration testing in controlled environments. Students apply structured penetration testing methodologies to scope engagements, gather intelligence, identify vulnerabilities, validate exploitability and communicate findings. The unit also explores web, mobile and application security testing, the use of contemporary tools such as Kali Linux and Metasploit, and emerging issues such as vulnerabilities introduced by AI-generated code and AI-assisted offensive techniques.

The aim of this unit is to develop students’ capacity to plan and conduct authorised penetration testing activities, evaluate security weaknesses, and communicate technically sound and ethically responsible findings and recommendations.

2027 10

Campus offering

No unit offerings are currently available for this unit.

Prerequisites

ITEC614 Cyber Security Concepts AND ITEC611 Computer Networks

Learning outcomes

To successfully complete this unit you will be able to demonstrate you have achieved the learning outcomes (LO) detailed in the below table.

Each outcome is informed by a number of graduate capabilities (GC) to ensure your work in this, and every unit, is part of a larger goal of graduating from ACU with the attributes of insight, empathy, imagination and impact.

Explore the graduate capabilities.

Apply structured penetration testing methodologies...

Learning Outcome 01

Apply structured penetration testing methodologies for scope engagements, and reconnaissance and vulnerability assessment in controlled environments.
Relevant Graduate Capabilities: GC2, GC8

Evaluate vulnerabilities through authorised exploi...

Learning Outcome 02

Evaluate vulnerabilities through authorised exploitation techniques using contemporary offensive security tools and methods.
Relevant Graduate Capabilities: GC1, GC10

Produce professional penetration testing reports ...

Learning Outcome 03

Produce professional penetration testing reports with evidence-based remediation recommendations for technical and non-technical stakeholders.
Relevant Graduate Capabilities: GC2, GC11

Critically evaluate legal, ethical and professiona...

Learning Outcome 04

Critically evaluate legal, ethical and professional issues in offensive security practices
Relevant Graduate Capabilities: GC1, GC6

Content

Topics will include:

Penetration testing foundations

Authorisation, scope, rules of engagement, penetration testing methodologies, and professional standards.

Reconnaissance and vulnerability assessment

Open-source intelligence (OSINT), scanning, enumeration, attack-surface analysis, and vulnerability identification and validation.

Controlled exploitation and post-exploitation

Exploitation techniques including SQL injection, buffer overflow and race condition vulnerabilities; privilege escalation, lateral movement, persistence risks, and safe lab-based validation.

Web, application and enterprise security testing

OWASP-aligned testing, common web vulnerabilities, exploitation workflows, remediation strategies, and enterprise-focused topics such as Active Directory attacks and misconfiguration exploitation.

AI-related offensive security issues

AI-assisted attack techniques, vulnerabilities introduced by AI-generated code, and risks in AI-supported testing workflows.

Reporting, remediation and professional practice

Writing penetration testing reports, communicating findings to stakeholders, responsible disclosure, and legal, ethical and professional considerations in offensive security practice.

Assessment strategy and rationale

The assessment strategy is designed to progressively develop students’ capability from planning and analysis to applied testing and critical professional judgement. Assessment 1 requires students to scope an authorised engagement and conduct reconnaissance and vulnerability assessment, developing foundational capability in penetration testing methodology and evidence gathering. Assessment 2 then requires students to perform controlled exploitation and analyse findings in a laboratory environment, demonstrating technical competence and interpretive skill. Assessment 3 requires students to critically evaluate a complex offensive security scenario involving legal, ethical, reporting and AI-related issues, and justify an appropriate professional response. Together, the assessments provide a coherent progression from analysis to application to advanced evaluation, and support achievement of all learning outcomes. To pass this unit, students must demonstrate competence in all learning outcomes and achieve an aggregate mark of at least 50%.

Overview of assessments

Task 1: Penetration testing plan and reconnaissan...

Task 1:Penetration testing plan and reconnaissance report

Students prepare a scoped penetration testing plan for a realistic target environment and conduct authorised reconnaissance, enumeration and vulnerability assessment. They document assumptions, scope boundaries, tools, evidence and initial findings, and justify the proposed testing approach.

Submission Type: Individual

Assessment Method: Written

Artefact: report (1000 words)

Weighting

20%

Learning Outcomes LO1
Graduate Capabilities GC2, GC8

Task 2: Applied penetration testing report Stud...

Task 2: Applied penetration testing report

Students conduct controlled exploitation activities in a sandboxed environment using approved tools and techniques. They analyse the evidence collected, validate vulnerabilities, assess impact, and produce a professional report with remediation recommendations.

Submission Type: Individual

Assessment Method: Report+Presentation

Artefact: 1000 words plus technical appendix/screenshots+ Live / Recorded with face-overlay Presentation (5 minutes) + Online Viva

Weighting

40%

Learning Outcomes LO2, LO3
Graduate Capabilities GC1, GC2, GC10, GC11

Task 3: Critical professional case analysisStude...

Task 3: Critical professional case analysis

Students critically evaluate a complex offensive security scenario involving issues such as authorisation, disclosure, AI-assisted exploit development. They justify an ethically and professionally defensible course of action for both technical and organisational stakeholders.

Submission Type: Individual

Assessment Method: Written Report and Presentation

Artefact: 1000 words plus technical appendix/screenshots+ Live / Recorded with face-overlay Presentation (5 minutes) + Online Viva

Weighting

40%

Learning Outcomes LO1, LO2, LO3, LO4
Graduate Capabilities GC1, GC2, GC6, GC8, GC10, GC11

Learning and teaching strategy and rationale

This unit is delivered fully online, primarily in an asynchronous mode, through recorded lectures, guided learning resources, virtual lab activities, case-based learning and discussion forums. Students engage in authorised, sandboxed offensive security exercises designed to develop methodological rigour, technical capability and professional judgement. Learning activities support AQF Level 9 expectations by requiring students to analyse complex security scenarios, justify testing decisions, interpret technical evidence and communicate findings responsibly. To further support student learning, up to three optional synchronous online workshops will be offered during the unit for assessment consultation and clarification.

Students should plan to commit approximately 150 hours to this unit over the semester, including participation in learning activities, independent study, readings and assessment preparation.

Representative texts and references

Representative texts and references

Abdollahi, A. (2025). A beginner’s guide to web application penetration testing. Wiley.

Baloch, R. (2025). Web hacking arsenal: A practical guide to modern web pentesting. CRC Press.

Basta, A., Basta, N., & Anwar, W. (2024). Pen testing from contract to report. Wiley.

Maurer, P. J., & Skoudis, E. (2024). The code of honor: Embracing ethics in cybersecurity. Wiley.

OWASP Foundation. (2025). OWASP application security verification standard (ASVS) 5.0.

Cody, T., Nandakumar, D., Radke, D., Shetty, S., Redino, C., & Rahman, A. (2024). Reinforcement learning for cyber operations: Applications of artificial intelligence for penetration testing. Wiley-IEEE Press.

Manjikian, M. (2023). Cybersecurity ethics: An introduction (2nd ed.). Routledge.

National Institute of Standards and Technology. (2024). Artificial intelligence risk management framework: Generative artificial intelligence profile (NIST AI 600-1). U.S. Department of Commerce.

OWASP Foundation. (n.d.). OWASP web security testing guide.

Penetration Testing Execution Standard. (n.d.). PTES technical guidelines

Locations
Credit points
Year

Have a question?

We're available 9am–5pm AEST,
Monday to Friday

If you’ve got a question, our AskACU team has you covered. You can search FAQs, email, live chat, call – whatever works for you.

Live chat with us now

Chat to our team for real-time
answers to your questions.

Launch live chat

Visit our FAQs page

Find answers to some commonly
asked questions.

See our FAQs