| Effective Term: | 2027/05 |
| Institute / School : | Institute of Innovation, Science & Sustainability |
| Unit Title: | Vulnerability Assessment and Penetration Testing |
| Unit ID: | ITECH2507 |
| Credit Points: | 15.00 |
| Prerequisite(s): | (ITECH1502) |
| Co-requisite(s): | Nil |
| Exclusion(s): | Nil |
| ASCED: | 020113 |
| Other Change: | |
| Brief description of the Unit |
This unit delves into Vulnerability Assessments (VAs) and Penetration Testing (Pen Testing), equipping students with advanced skills and deep knowledge to proactively identify and address security vulnerabilities in computer systems and networks. Analyze vulnerabilities, evaluate penetration testing methodologies, and design & execute ethical penetration tests. Explore advanced topics like cloud security and social engineering, then craft effective countermeasures and mitigation strategies. The unit concludes with penetration testing frameworks and report creation, culminating in a project where you apply your skills in a simulated environment. |
| Grade Scheme: | Graded (HD, D, C, P, MF, F, XF) |
| Work Experience Indicator: |
| No work experience |
| Placement Component: | |
| Supplementary Assessment:Yes |
| Where supplementary assessment is available a student must have failed overall in the Unit but gained a final mark of 45 per cent or above, has completed all major assessment tasks (including all sub-components where a task has multiple parts) as specified in the Unit Description and is not eligible for any other form of supplementary assessment |
| Course Level: |
| Level of Unit in Course | AQF Level(s) of Course | | 5 | 6 | 7 | 8 | 9 | 10 | | Introductory | | | | | | | | Intermediate | | | | | | | | Advanced | | | | | | |
|
| Learning Outcomes: |
| Knowledge: |
| Skills: |
| Application of knowledge and skills: |
| Other outcomes: |
| O1. | Analyze the root causes of and security implications of system and network vulnerabilties, considering organisational and societal impact. |
|
| O2. | Evaluate and select penetration testing methodologies and tools, justifying their appropriateness for specific contexts and compliance requirements. |
|
| O3. | Assess and prioritise identified vulnerabilities based on exploitability, business risk, and legal/ethical frameworks governing authorised testing. |
|
| O4. | Compare and contrast leading vulnerability assessment tools, critically evaluating their suitability for different network configurations and security needs. |
|
| O5. | Produce a professional penetration testing report that clearly communicates findings, evaluates organisational risk, and recommends mitigation strategies aligned with legal and ethical obligations. |
|
| Unit Content: |
Topics may include:
1. Introduction to VAs & Pen Testing, Ethical Hacking Principles, Regulatory Compliance
2. Vulnerability assessment and penetration testing Life Cycle
3. Vulnerability Scanner Types & Methodologies
4. Prioritizing Vulnerabilities based on Severity & Exploitability
5. Reconnaissance Techniques like Information Gathering, and Footprinting
6. Enumeration Techniques like Identifying Services, Systems, Users
7. Gaining Initial Access (Exploiting Vulnerabilities, Social Engineering)
8. Privilege Escalation Techniques
9. Security Testing Techniques and Methodologies including web applications and wireless networks
10. Penetration Testing Frameworks & Reporting Standards |
| Graduate Attributes: |
| | Learning Outcomes Assessed | Assessment Tasks | Assessment Type | Weighting | Professional Standards |
| 1. |
1, 2, 3 |
Lab Reports: Following each hands-on lab session, students will submit a lab report documenting their work. Reports should detail the tools used, the procedures followed, the results obtained, and any challenges encountered. |
Lab Reports |
20%-40% |
1.6, 1.5 |
| 2. |
1, 3, 4 |
Students complete a practical investigation involving a simuulated vulnerability assessment task in a student selected industry. This task demonstrates their abilities related to tool selection, analysis of scan results and selection of the most critical vulnerabilities. |
Vulnerability Assessment Project |
20%-40% |
1.6, 2.1, 2.4 |
| 3. |
2, 3, 5 |
Students demonstrate their ability to perform a penetration testing project, by working through each step in the PT methodology, including tool selection, triage of results, and production of a professional penetration testing report. |
Penetration Testing Capstone Demonstration |
30%-50% |
1.6, 2.1, 2.4 |
|