Welcome — welcome to PhoenixLearniVerse

22 credits · Self-paced

Ethical Hacking & Penetration Testing

CEH/OSCP-aligned offensive security.

Reconnaissance, exploitation, post-exploitation and reporting under ethical & legal frameworks.

Available in your language:

Curriculum

  1. 01Ethics, law & scoping15 min+

    Ethics, law & scoping

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Ethics, law & scoping as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Ethics, law & scoping in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Ethics, law & scoping.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  2. 02Reconnaissance & OSINT15 min+

    Reconnaissance & OSINT

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Reconnaissance & OSINT as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Reconnaissance & OSINT in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Reconnaissance & OSINT.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  3. 03Scanning & enumeration15 min+

    Scanning & enumeration

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Scanning & enumeration as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Scanning & enumeration in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Scanning & enumeration.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  4. 04Exploitation fundamentals15 min+

    Exploitation fundamentals

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Exploitation fundamentals as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Exploitation fundamentals in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Exploitation fundamentals.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  5. 05Web application testing15 min+

    Web application testing

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Web application testing as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Web application testing in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Web application testing.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  6. 06Post-exploitation & privilege escalation15 min+

    Post-exploitation & privilege escalation

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Post-exploitation & privilege escalation as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Post-exploitation & privilege escalation in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Post-exploitation & privilege escalation.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  7. 07Reporting & remediation15 min+

    Reporting & remediation

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Reporting & remediation as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Reporting & remediation in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Reporting & remediation.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.

  8. 08Capstone CTF15 min+

    Capstone CTF

    Module of "Ethical Hacking & Penetration Testing" — Phoenix Learning Cloud

    Overview

    This module gives you a rigorous, globally benchmarked treatment of Capstone CTF as it applies to Ethical Hacking & Penetration Testing. Content is aligned to leading international standards and current industry practice (ISO, IEEE, PMBOK, CFA Institute, FATF, NIST, OECD, WHO, IFRS, GDPR, ITIL 4, CEFR and equivalent frameworks where relevant), and structured around Bloom's taxonomy so that you move from understanding to application, analysis and evaluation.

    Learning Outcomes

    By the end of this module you will be able to:

    1. Explain the core concepts, terminology and history underpinning Capstone CTF in the context of Ethical Hacking & Penetration Testing.
    2. Apply recognised international frameworks, standards and best practices to real-world problems in this area.
    3. Analyse case studies drawn from Europe, North America, the Middle East, Africa and Asia-Pacific to identify what works, what fails, and why.
    4. Design a defensible plan, artefact or decision using the tools, templates and checklists introduced in the module.
    5. Evaluate your work against ethical, legal, security, sustainability and inclusion criteria.

    Topics Covered

    • Foundational concepts, vocabulary and historical evolution of Capstone CTF.
    • Global frameworks, regulations and reference architectures relevant to Ethical Hacking & Penetration Testing.
    • Key roles, responsibilities and stakeholder maps.
    • Processes, workflows and decision points, illustrated with annotated diagrams.
    • Tools, platforms and methods currently used by leading organisations.
    • Metrics, KPIs and quality criteria used to measure success.
    • Common failure modes, anti-patterns and mitigation strategies.
    • Cross-cutting concerns: ethics, security, privacy, accessibility, DEI and sustainability.
    • Emerging trends (AI, automation, regulation, geopolitics) and how they reshape practice.

    Global Standards & References

    • ISO / IEC standards relevant to the topic (e.g. ISO 9001, ISO 27001, ISO 31000, ISO 20000, ISO 14001 as applicable).
    • Sector bodies: PMI (PMBOK 7), CFA Institute, ACCA, IIA, FATF, NIST, ENISA, WHO, IFRS Foundation, OECD, UN SDGs, ITIL 4, TOGAF, IEEE, W3C, CEFR.
    • Landmark legislation and guidance: GDPR, UK Data Protection Act, HIPAA, SOX, Basel III/IV, MiFID II, EU AI Act, DORA.
    • Recognised textbooks, whitepapers and peer-reviewed journals cited in each lesson video.

    Activities & Practical Work

    • Guided walkthrough of a real-world scenario using a downloadable template.
    • Case study analysis with structured questions and a marking rubric.
    • Hands-on lab or workshop task producing a portfolio artefact (plan, model, code, policy, or design).
    • Peer discussion prompt in the Phoenix community for cross-industry perspectives.
    • Reflection journal to convert new knowledge into personal action.

    Assessment

    • Knowledge check quiz (10 questions, 70% pass mark, unlimited retakes).
    • Applied assignment graded against a competency rubric (submit for instructor or peer review).
    • Contribution to the module discussion counts toward the participation grade.
    • Successful completion contributes credits toward your Phoenix Learning Cloud certificate for Ethical Hacking & Penetration Testing, which is QR-verifiable and issued upon passing the end-of-course assessment.

    Estimated Effort

    Approximately 3–5 hours of study, plus 1–2 hours of practical work. All content is available in your chosen platform language and can be resumed at any time from My Learning.

    Next Steps

    Complete the quiz, submit the applied assignment, and continue to the next module. Struggling with a concept? Ask the built-in AI Tutor or post in the community — instructors respond within one business day.