Module Outline

Date retreived
22/07/2026 12:51 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Perform advanced penetration testing for web site vulnerabilities

Perform advanced penetration testing for web site vulnerabilities

Module
National Code
VU23302
State Code
AZ594
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
80
Description
This unit describes the performance outcomes, skills and knowledge required to expand the testing capability for web vulnerabilities. It includes skills in using advanced features of current toolsets in order to identify weaknesses in the security of an organisation’s website.

It requires the ability to utilise the current security framework Open Web Application Security Project (OWASP) security methodology and open source tools to provide a sound foundation to develop these skills.

The unit applies to cyber security practitioners who are required to use advanced testing tools to determine vulnerabilities in an organisation’s web site.

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Comprehend the web application development process
  • Examples of web frameworks are reviewed
  • Web application development process is explained
  • Web application development environment and associated test phases are determined
  • Web architecture concepts are reviewed
Utilise tools and technology for testing web site content
  • Tools used to determine the technology stack used in web applications and web servers are utilised
  • Custom wordlists for spidering are created
  • Value of user-agent strings used in testing tools are evaluated
  • Identifying the technology stack of a web application utilising current resources are investigated
Examine the advanced features of a current proxy testing tool suite
  • Review of a current proxy tool suite is demonstrated
  • Dangers of live scanning are explained
  • Utilising extended features of a current proxy testing tool, the vulnerabilities of the organisation’s web site are explored
Perform vulnerability scanning
  • Difference between automated testing and manual testing is compared
  • Use of an automated web application scanner to test an application is demonstrated
  • Results from the automated scanner report are interpreted
  • Use of manual testing of a web application is explored
Identify common web application vulnerabilities
  • Common web application vulnerabilities are reviewed
  • Content and vulnerabilities of Content Management Systems and plugin are investigated
  • Remediation strategies to mitigate the defined web application vulnerabilities are formulated
  • Vulnerabilities for software rework are reported to the developer
Exploit web application vulnerabilities
  • Testing tools and manual methods used to exploit web application vulnerabilities are selected
  • Advantages and disadvantages of web application testing tools are evaluated
  • Use of testing tool operation to exploit web site vulnerabilities is demonstrated
Replaces
State Code National Code Title Type
AX660 VU22254 Undertake advanced penetration testing for web site vulnerabilities Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course