Accredited course Outline
22/07/2026 7:11 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Certificate IV in Offensive Cyber Security
Certificate IV in Offensive Cyber Security
11062NAT
BGS59
Current
Approved
State Implementation and Classification
Description
The Certificate IV in Offensive Cyber Security is designed to train individuals in conducting vulnerability assessment through offensive cyber security, otherwise known as ethical hacking/penetration testing for the specific purpose of mitigating risks to infrastructure, networks, and applications.
It will provide participants with a range of skills and knowledge needed to find and exploit vulnerabilities in the IT infrastructure, networks, and applications of a range of organisations in multiple industries to find and demonstrate weaknesses in those systems. This will allow organisations to implement security measures and strengthen ICT systems to reduce the likelihood and impact of malicious cyber-attacks.
Schedule
Total number of units = Thirteen (13)
- Ten (10) core units, plus
- Three (3) elective units from one of the specialisation groups listed below.
Note:
1. Core units must be undertaken in the order listed.
2. This course provides two specialisations, one of which must be chosen to complete the 11062NAT Certificate IV in Offensive Cyber Security.
To achieve the specialisation, the following rules must be adhered to.
To specialise in infrastructure, all three elective units in Group A must be completed.
To specialise in applications, all three elective units in Group B must be completed.
The achievement of the specialisation will be identified on a testamur as follows:
● Certificate IV in Offensive Cyber Security (Infrastructure Vulnerability Assessment Specialist)
● Certificate IV in Offensive Cyber Security (Application Vulnerability Assessment Specialist).
1. Core Units
Ten (10) must be completed in the below order:
- NAT11062001 Apply legal requirements and ethical protocols during offensive cyber security activities
- ICTNWK420 Install and configure virtual machines
- ICTWEB444 Create responsive website layouts
- ICTWEB430 Produce server-side script for dynamic web pages
- ICTPRG430 Apply introductory object-oriented language skills
- NAT11062002 Develop and implement programs and scripts for offensive cyber security
- ICTNWK311 Install and test network protocols
- NAT11062003 Test vulnerability of organisational networks
- NAT11062004 Test vulnerability of organisational operating systems
- ICTCYS603 Undertake penetration testing for organisations
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| OAQ05 | ICTPRG430 | Apply introductory object-oriented language skills | 60 | Unit of competency |
| BA040 | NAT11062001 | Apply legal requirements and ethical protocols during offensive cyber security activities | 15 | Module |
| OBS24 | ICTWEB444 | Create responsive website layouts | 50 | Unit of competency |
| BA042 | NAT11062002 | Develop and implement programs and scripts for offensive cyber security | 70 | Module |
| OAQ06 | ICTNWK420 | Install and configure virtual machines | 50 | Unit of competency |
| OBT78 | ICTNWK311 | Install and test network protocols | 30 | Unit of competency |
| OAQ01 | ICTWEB430 | Produce server-side script for dynamic web pages | 60 | Unit of competency |
| BA044 | NAT11062003 | Test vulnerability of organisational networks | 40 | Module |
| BA046 | NAT11062004 | Test vulnerability of organisational operating systems | 40 | Module |
| OBV07 | ICTCYS603 | Undertake penetration testing for organisations | 70 | Unit of competency |
2. Group A: Infrastructure Vulnerability Assessment Specialist
To specialise in infrastructure, all three (3) elective units in Group A must be completed.
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| BA050 | NAT11062006 | Implement privilege escalation in Linux operating systems | 15 | Module |
| BA048 | NAT11062005 | Implement privilege escalation in Windows operating systems | 15 | Module |
| BA052 | NAT11062007 | Infiltrate and test organisational digital environments | 50 | Module |
3. Group B: Application Vulnerability Assessment Specialist
To specialise in applications, all three (3) elective units in Group B must be completed.
| State Code | National Code | Title | Hours | Type |
|---|---|---|---|---|
| BA058 | NAT11062010 | Analyse malware using reverse engineering software tools and techniques | 50 | Module |
| BA056 | NAT11062009 | Exploit cross-platform vulnerabilities in mobile applications | 40 | Module |
| BA054 | NAT11062008 | Exploit web application vulnerabilities | 60 | Module |