Learning Outcomes
- Establish lawful authority, ethical boundaries, professional conduct, privacy controls, responsible disclosure, and stop conditions for a VAPT engagement.
- Translate business risk questions into a bounded assessment plan, rules of engagement, communications matrix, safe laboratory design, evidence plan, and acceptance criteria.
- Build an evidence-led attack-surface inventory from supplied passive and active discovery records while reconciling ownership, exposure, uncertainty, and scope.
- Interpret and validate network, host, service, and configuration findings using proportionate enumeration, independent checks, and documented limitations.
- Design, tune, and quality-control vulnerability scanning; separate coverage from assurance and convert tool output into verified candidate findings.
- Assess web applications against a risk-based, versioned test plan covering architecture, configuration, identity, session, access control, input handling, business logic, and client behavior.
- Assess APIs and service interfaces using inventories, schemas, object- and function-level authorization tests, rate controls, data exposure checks, and safe negative cases.
- Evaluate identity, authentication, authorization, wireless, and human-layer control evidence without collecting real credentials or conducting unsanctioned social engineering.
- Plan and document controlled proof-of-concept validation using the least-impact method, explicit constraints, rollback, evidence minimization, and immediate stop rules.
- Analyze vulnerability significance using CVSS v4.0, asset context, exploit evidence, exposure, compensating controls, business impact, and uncertainty to support defensible prioritization.
- Write decision-ready technical and executive reports, recommend verifiable remediation, manage disclosure, perform quality review, and conduct bounded retesting.
- Complete an authorization-to-retest VAPT capstone that integrates scope, discovery, validation, risk analysis, reporting, remediation verification, evidence handling, and lessons learned.
Certificate : DTF AI Academy
Course Features
- Lectures 72
- Quizzes 13
- Duration 10 weeks
- Skill level All levels
- Language English
- Students 6
- Certificate Yes
- Assessments Self
- 13 Sections
- 72 Lessons
- 10 Weeks
- Authority, Ethics, Law, and Professional Conduct
Outcome: Establish lawful authority, ethical boundaries, professional conduct, privacy controls, responsible disclosure, and stop conditions for a VAPT engagement.
Case: Northbridge asks a tester to assess a customer portal, but the request is verbal, the portal is hosted by a third party, and no scope, window, data rule, or emergency contact has been approved.
Tools: Authorization gate, Rules-of-engagement review, Stop-and-escalate drill
7- 1.1Ethical hacking begins with permission
- 1.2Indian cyber-law context changes the risk
- 1.3Rules of engagement translate permission into constraints
- 1.4Safety and privacy duties continue during testing
- 1.5Stop conditions protect people and operations
- 1.6Responsible disclosure is a controlled communication
- 1.7Module 1 Assessment — Authority, Ethics, Law, and Professional Conduct5 Minutes5 Questions
- Engagement Planning, Rules of Engagement, and Safe Operations
Outcome: Translate business risk questions into a bounded assessment plan, rules of engagement, communications matrix, safe laboratory design, evidence plan, and acceptance criteria.
Case: Northbridge has an isolated training replica and a two-day assessment window, but objectives, test accounts, source addresses, monitoring expectations, backups, evidence storage, and restoration ownership are incomplete.
Tools: Assessment plan, ROE quality checklist, Lab and communications readiness register
7- 2.1A test plan connects objectives to evidence
- 2.2Isolation is the first lab control
- 2.3Pre-engagement checks prevent avoidable incidents
- 2.4Testing follows a controlled lifecycle
- 2.5Evidence should be reproducible and sanitized
- 2.6Tool choice follows risk, not fashion
- 2.7Module 2 Assessment — Engagement Planning, Rules of Engagement, and Safe Operations5 Minutes5 Questions
- Asset Discovery and Attack-Surface Mapping
Outcome: Build an evidence-led attack-surface inventory from supplied passive and active discovery records while reconciling ownership, exposure, uncertainty, and scope.
Case: A supplied Northbridge asset register, DNS export, certificate inventory, cloud list, network diagram, and low-rate discovery log disagree about which systems exist and who owns them.
Tools: Scope-to-asset matrix, Attack-surface map, Ownership and uncertainty register
7- 3.1Start with declared scope and ownership
- 3.2Use passive evidence before active discovery
- 3.3Map domains, addresses, services, applications, and dependencies
- 3.4Reconcile cloud, API, and external exposure
- 3.5Prioritize discovery gaps
- 3.6Produce a traceable attack-surface baseline
- 3.7Module 3 Assessment — Asset Discovery and Attack-Surface Mapping5 Minutes5 Questions
- Network, Host, Service, and Configuration Assessment
Outcome: Interpret and validate network, host, service, and configuration findings using proportionate enumeration, independent checks, and documented limitations.
Case: Northbridge supplies packet summaries, service banners, configuration extracts, and scanner candidates from an isolated segment. Several versions are masked, two services are fragile, and one finding conflicts with the configuration record.
Tools: Service validation matrix, Configuration review checklist, False-positive resolution log
7- 4.1Scanning is measurement with side effects
- 4.2Service enumeration turns ports into hypotheses
- 4.3Vulnerability scanners have coverage limits
- 4.4Validation should be bounded and non-destructive
- 4.5Risk combines likelihood, impact, and context
- 4.6Triage produces an actionable queue
- 4.7Module 4 Assessment — Network, Host, Service, and Configuration Assessment5 Minutes5 Questions
- Vulnerability Scanning, Validation, and Coverage
Outcome: Design, tune, and quality-control vulnerability scanning; separate coverage from assurance and convert tool output into verified candidate findings.
Case: Two approved scanners produce different results against the same synthetic environment. One scan used credentials, one was unauthenticated, coverage gaps exist, and several high-severity results are unverified.
Tools: Scan design sheet, Candidate-finding register, Coverage and validation dashboard
7- 5.1Design scans from objectives and asset behavior
- 5.2Control scanner identity, credentials, and secrets
- 5.3Interpret signatures and confidence
- 5.4Validate safely and preserve negative results
- 5.5Measure coverage and blind spots
- 5.6Manage rescans and change
- 5.7Module 5 Assessment — Vulnerability Scanning, Validation, and Coverage5 Minutes5 Questions
- Web Application Security Assessment
Outcome: Assess web applications against a risk-based, versioned test plan covering architecture, configuration, identity, session, access control, input handling, business logic, and client behavior.
Case: Northbridge provides an isolated portal replica, test roles, data-flow diagram, request collection, and versioned requirements. The tester must build coverage and verify findings without accessing real users or destructive functions.
Tools: WSTG-ASVS test matrix, Request and evidence log, Business-logic casebook
7- 6.1Map the application before testing controls
- 6.2OWASP Top 10:2025 is an awareness lens
- 6.3Authentication and sessions must work together
- 6.4Authorization must be enforced server-side
- 6.5Input handling should preserve intent
- 6.6Business logic needs human reasoning
- 6.7Module 6 Assessment — Web Application Security Assessment5 Minutes5 Questions
- API and Service Interface Assessment
Outcome: Assess APIs and service interfaces using inventories, schemas, object- and function-level authorization tests, rate controls, data exposure checks, and safe negative cases.
Case: A synthetic Northbridge API has documented and undocumented routes, three test roles, predictable object identifiers, asynchronous jobs, rate controls, and a legacy integration account.
Tools: API inventory, Authorization test matrix, Schema and negative-test worksheet
7- 7.1Inventory APIs, versions, schemas, and trust boundaries
- 7.2Test object-level authorization with synthetic roles
- 7.3Test function-level authorization and workflow state
- 7.4Evaluate authentication, tokens, and session behavior
- 7.5Assess resource consumption and abuse controls
- 7.6Assess data exposure, inventory, and unsafe dependencies
- 7.7Module 7 Assessment — API and Service Interface Assessment5 Minutes5 Questions
- Identity, Authentication, Wireless, and Human-Layer Controls
Outcome: Evaluate identity, authentication, authorization, wireless, and human-layer control evidence without collecting real credentials or conducting unsanctioned social engineering.
Case: Northbridge supplies synthetic identity logs, role matrices, password-policy evidence, wireless configurations, and approved awareness simulations. No real accounts, live wireless networks, or staff interactions are permitted.
Tools: Identity test matrix, Wireless configuration review, Simulation ethics checklist
7- 8.1Password security is a system property
- 8.2Credential testing requires special authorization
- 8.3MFA changes but does not eliminate risk
- 8.4Wireless assessment starts with ownership and architecture
- 8.5Social engineering tests people and process
- 8.6Human-layer findings should improve systems
- 8.7Module 8 Assessment — Identity, Authentication, Wireless, and Human-Layer Controls5 Minutes5 Questions
- Controlled Exploitation and Impact Validation
Outcome: Plan and document controlled proof-of-concept validation using the least-impact method, explicit constraints, rollback, evidence minimization, and immediate stop rules.
Case: A confirmed vulnerability exists in an isolated Northbridge replica. The engagement lead needs a bounded proof of impact, but persistence, credential dumping, lateral movement, destructive actions, stealth, and production data are prohibited.
Tools: Proof-of-concept approval record, Impact evidence sheet, Rollback and cleanup checklist
7- 9.1Exploitation validates a security consequence
- 9.2Proof of concept should minimize change
- 9.3Privilege escalation is a control-chain failure
- 9.4Lateral movement depends on trust and credentials
- 9.5ATT&CK turns observations into defensive language
- 9.6Cleanup and restoration close the test
- 9.7Module 9 Assessment — Controlled Exploitation and Impact Validation5 Minutes5 Questions
- Risk Analysis, CVSS v4.0, and Prioritization
Outcome: Analyze vulnerability significance using CVSS v4.0, asset context, exploit evidence, exposure, compensating controls, business impact, and uncertainty to support defensible prioritization.
Case: Northbridge has forty verified findings, limited remediation capacity, mixed business criticality, two CISA KEV matches, compensating controls, and conflicting stakeholder priorities.
Tools: CVSS v4 worksheet, Contextual risk matrix, Remediation decision register
7- 10.1Separate severity, threat, exposure, and business risk
- 10.2Apply CVSS v4.0 consistently
- 10.3Use exploit and threat evidence carefully
- 10.4Model exposure and compensating controls
- 10.5Prioritize remediation portfolios
- 10.6Communicate uncertainty and decision rationale
- 10.7Module 10 Assessment — Risk Analysis, CVSS v4.0, and Prioritization5 Minutes5 Questions
- Reporting, Remediation, Disclosure, and Retesting
Outcome: Write decision-ready technical and executive reports, recommend verifiable remediation, manage disclosure, perform quality review, and conduct bounded retesting.
Case: Northbridge needs a technical report, executive brief, remediation backlog, disclosure decision, and retest record. Several findings share a root cause, one includes sensitive evidence, and one remediation changes architecture.
Tools: Finding quality rubric, Remediation verification plan, Report and disclosure review
7- 11.1A finding is a defensible argument
- 11.2Severity needs transparent reasoning
- 11.3Recommendations should be actionable
- 11.4Executive communication is concise and honest
- 11.5Retesting verifies closure
- 11.6Capstone: conduct a bounded foundation assessment
- 11.7Module 11 Assessment — Reporting, Remediation, Disclosure, and Retesting5 Minutes5 Questions
- Professional VAPT Capstone
Outcome: Complete an authorization-to-retest VAPT capstone that integrates scope, discovery, validation, risk analysis, reporting, remediation verification, evidence handling, and lessons learned.
Case: The final Northbridge engagement combines authority records, scope changes, asset inventories, scanner output, web and API evidence, a bounded proof-of-concept request, CVSS data, business context, reviewer comments, remediation evidence, and a fixed executive deadline.
Tools: Engagement control file, Finding and risk register, Authorization-to-retest capstone
7 - Final ExaminationFinal assessment for Vulnerability Assessment & Penetration Testing. Passing score: 70%.1
Certificate



