Module Outline
Date retreived
23/07/2026 5:22 AM AWST
23/07/2026 5:22 AM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Identify Active Directory security concepts
Identify Active Directory security concepts
Module
National Code
VU23308
VU23308
State Code
AZ613
AZ613
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
60
Description
This unit describes the performance outcomes, skills and knowledge required to enable participants to firstly, become familiar with the architecture of Active Directory (AD) then to identify areas of security vulnerability.
It requires the ability to define AD physical structure together with the roles of the protocols used. The unit also includes the tactics, techniques, and procedures (TTP’s) used to compromise AD accounts as well as methods of securing and defending AD including developing safe AD working practices.
The unit applies to cyber security practitioners who, as part of a team responds to cyber security incidents in an organisation.
No licensing or certification requirements apply to this unit at the time of accreditation.
It requires the ability to define AD physical structure together with the roles of the protocols used. The unit also includes the tactics, techniques, and procedures (TTP’s) used to compromise AD accounts as well as methods of securing and defending AD including developing safe AD working practices.
The unit applies to cyber security practitioners who, as part of a team responds to cyber security incidents in an organisation.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Identity Access Management (AM) fundamentals
- Differences between identities, accounts, access, authorisation and authentication are identified
- Identity lifecycle management process is defined
- Function and operation of common authentication services are compared
- Types of authorisation processes are identified
- Accountability and audit concepts, such as access logging and audit trails are identified
- Current trends in identity determination such as Multi Factor Authentication (MFA) are investigated
Investigate AD architecture
- Logical structure of an AD is identified
- AD physical structure is defined
- Roles of the protocols used in AD are defined
- Mechanics of AD are described
- Structure of privileged accounts and groups in AD are examined
- Group Policy Objects (GPO’s) configuration issues especially if applying to the domain root or domain controller are identified
- Cloud connectivity using Active Directory Federation Services (ADFS) is identified
- Cloud connectivity of AD to Azure Active Directory (AAD) connect is performed
Define the basic structure of Windows security
- Windows services and scheduled tasks are identified
- Differences between Local user and Local Administrator accounts is defined
- Function and role of Local Security the Authority Server Service (LSASS) in a Windows environment is identified
Investigate attack techniques on Microsoft end-points (workstations and servers)
- Common end point attack techniques on end points are identified
- Privilege escalation using credential dumping tools are examined
- Common lateral movement techniques are identified
- Fileless attack tools and techniques on AD are defined
Investigate attack techniques on AD
- Compromising methods for AD accounts are defined
- AD accounts that are attractive to compromise are identified
- Systems and processes to minimise compromising AD accounts are defined
- Tactics, techniques, and procedures (TTP’s) used to compromise AD accounts are identified
- Insecure Windows protocols are identified
Investigate securing and defending AD from cyber attacks
- Methods of securing AD are investigated
- AD monitoring tools and techniques for signs of compromise are investigated
- AD attack patterns determined from logs are identified
- Role of User and Entity Behaviour Analytics (UEBA) and Endpoint Detection and Response (EDR) tools are identified
Develop safe AD working practices
- Methods to protect keyboard entries are investigated
- Clean source code build strategies are investigated
- Zero Trust mechanics processes are investigated
- Privileged access management principles are investigated
- Methods to harden the environment against compromise are examined
- Use of Credential Guard and how it protects LSASS memory is examined
No information
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |