Module Outline

Date retreived
22/07/2026 2:53 PM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Undertake vulnerability and penetration testing for information technology infrastructure

Undertake vulnerability and penetration testing for information technology infrastructure

Module
National Code
VU23309
State Code
AZ614
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
80
Description
This unit describes the performance outcomes, skills and knowledge to expand the testing capability for information technology (IT) infrastructure vulnerabilities. Skills in using advanced features of current toolsets in order to identify weaknesses in the security of an organisation’s infrastructure are included.

It requires the ability to utilise the Kali security testing platform and open source tools to provide a sound foundation to develop these skills.

The unit applies to persons working as cyber security practitioners who use advanced testing tools to determine vulnerabilities in an organisation’s web site.

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Prepare for testing IT infrastructure
  • Processes and scope for conducting infrastructure vulnerability scanning and penetration testing are examined
  • Processes for conducting infrastructure vulnerability scanning and penetration testing are developed
  • Advantages, disadvantages, and dangers of penetration testing are identified
  • Process of note taking during a penetration test is examined
Perform vulnerability scanning of the infrastructure
  • Features of the selected vulnerability scanning tool are examined
  • Use of the selected vulnerability scanning tool is demonstrated
  • Results for the vulnerability scan report are interpreted
  • Identification of vulnerability remediation through patching or compensating controls is examined
Gather information using the testing tool
  • Information gathering using the Kali tools is demonstrated
  • Open Source intelligence (OSINT) using Kali’s tools is demonstrated
  • Information gathering using Kali’s testing tools is demonstrated
  • Vulnerability intelligence value of gathered information is assessed
Identify misconfigurations and weaknesses in the infrastructure
  • Common areas of infrastructure misconfiguration and weaknesses are identified and examined
  • Methods of exploiting misconfiguration and weaknesses are demonstrated
  • Use of Kali’s Database Assessment tools is demonstrated
  • Use of rootkits and trojan backdoors are examined
Exploit infrastructure vulnerabilities
  • Auxiliary scanning to identify additional vulnerabilities using Kali’s Metasploit tool is demonstrated
  • Exploitation of identified vulnerabilities using Kali’s Metasploit tool is demonstrated
  • Range of Kali’s Metasploit exploit payloads is examined
  • Use of Kali’s Metasploit encoders to hide payloads is demonstrated
  • Creation of shell payloads using Kali is demonstrated
Escalate privileges
  • Access and privilege models in Windows and Linux systems are examined
  • Use of Kali’s Metasploit exploits to escalate privileges is demonstrated
  • Use of open source proof of concept privilege escalation exploits is demonstrated
Exploitable vulnerabilities are mitigated
  • Remediation strategies to mitigate identified exploitable vulnerabilities are formulated
  • Hardening guides for key technologies are examined
No information
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course