Students

COMP3330 – Offensive Security and Ethical Hacking

2026 – Session 2, In person-scheduled-weekday, North Ryde

General Information

Download as PDF
Unit convenor and teaching staff Unit convenor and teaching staff Convenor and Lecturer
Damian Jurd
Contact via iLearn
Lecturer
Natasha Fernandes
Contact via iLearn
Credit points Credit points
10
Prerequisites Prerequisites
130cp at 1000-level or above and COMP2100 and COMP2110 and COMP2310 and COMP2300 and (COMP2250 or COMP2270)
Corequisites Corequisites
Co-badged status Co-badged status
Unit description Unit description

This unit provides an introduction to ethical hacking and offensive security. Strong emphasis is given to ethics and ethical behaviour as students are exposed to penetration techniques and methods. Specifically, students are taught how to systematically look for and exploit vulnerabilities in software, protocols, and systems in order to report those vulnerabilities and improve the safety of those software, protocols, and systems. Both written and verbal communication are emphasised as an essential part of any cyber-analytical role, and as such are a focus of the unit. The most proficient students in this unit may be selected to represent the University at various national and international penetration testing competitions and challenges.

The unit is intended to be a culmination of the technical and analytic skills acquired from a number of units in the Bachelor of Cyber Security, as such students should plan to take this unit as part of their final or penultimate session of study.

Learning in this unit enhances student understanding of global challenges identified by the United Nations Sustainable Development Goals (UNSDGs) Quality Education; Industry, Innovation and Infrastructure; Peace, Justice and Strong Institutions

Important Academic Dates

Information about important academic dates including deadlines for withdrawing from units are available at https://www.mq.edu.au/study/calendar-of-dates

Learning Outcomes

On successful completion of this unit, you will be able to:

  • ULO1: Explain the importance of ethics and ethical behaviour in relation to offensive security and penetration testing.
  • ULO2: Perform scoping, vulnerability scanning and reconnaissance on a range of devices, platforms, protocols, systems and organisations.
  • ULO3: Exploit vulnerabilities for a range of purposes, including access control, payload delivery and privilege escalation.
  • ULO4: Effectively communicate results to technical and non-technical audiences.
  • ULO5: Demonstrate the keeping and maintaining of an accurate and reflective record of activities undertaken as part of professional practice. 

General Assessment Information

Release Dates

  • Proficiency Assessment: information and sample questions are to be released no later than week 4
  • Professional Report - Preliminary Engagement: to be released no later than week 6
  • Professional Report - Supplementary Engagement: to be released no later than week 10

Requirements to Pass this Unit

To pass this unit, you must achieve a total mark equal to or greater than 50%.

Late Assessment Submission Penalty

Unless a Special Consideration request has been submitted and approved, a 5% penalty (of the total possible mark of the task) will be applied for each day a written report or presentation assessment is not submitted, up until the 7th day (including weekends). After the 7th day, a grade of ‘0’ will be awarded even if the assessment is submitted. The submission time for all uploaded assessments is 11:55 pm. A 1-hour grace period will be provided to students who experience technical concerns. For any late submission of time-sensitive tasks, such as scheduled tests/exams, performance assessments/presentations, and/or scheduled practical assessments/labs, please apply for Special Consideration. For example, if the assignment is worth 8 marks (of the entire unit) and your submission is late by 19 hours (or 23 hours 59 minutes 59 seconds), 0.4 marks (5% of 8 marks) will be deducted. If your submission is late by 24 hours (or 47 hours 59 minutes 59 seconds), 0.8 marks (10% of 8 marks) will be deducted, and so on.

Assessments where Late Submissions will be accepted

  • Proficiency Assessment - NO, this is an invigilated in-class assessment.

  • Professional Report - Preliminary Engagement - YES, Standard Late Penalty applies.

  • Professional Report - Supplementary Engagement - YES, Standard Late Penalty applies.

Short extensions

Short Extensions are not available for any assessments in this unit.

Special Consideration

The Special Consideration Policy aims to support students who have been impacted by short-term circumstances or events that are serious, unavoidable and significantly disruptive, and which may affect their performance in assessment. If you experience circumstances or events that affect your ability to complete the assessments in this unit on time, please inform the convenor and submit a Special Consideration request through http://connect.mq.edu.au/.

Generative AI Usage

The university has taken a ‘two lane’ approach with GenAI: assessments can be AI Open (meaning students complete the assessment in their own time and may use GenAI) and Observed (students complete assessments in supervised environments, where use of AI is controlled or not permitted). More information on the use of GenAI in Assessment can be found here.

In this unit the assessments fall into the two lanes as follows: 

  • Proficiency Assessment - AI Observed (this is an invigilated in-class assessment).

  • Professional Report - AI Open.

  • Professional Report - AI Open.

Assessment Tasks

Name Weighting Hurdle Due Groupwork/Individual Short Extension AI Approach
Proficiency Assessment 30% No 02/09/2026 Individual No Observed
Professional Report - Preliminary 30% No 25/09/2026 Individual No Open
Professional Report - Supplementary 40% No 13/11/2026 Individual No Open

Proficiency Assessment

Assessment Type 1: Examination
Indicative Time on Task 2: 6 hours
Due: 02/09/2026
Weighting: 30%
Groupwork/Individual: Individual
Short extension 3: No
AI Approach: Observed

You will be assessed on your knowledge of penetration testing tasks from a technical, methodological, and ethical perspective.


On successful completion you will be able to:
  • Explain the importance of ethics and ethical behaviour in relation to offensive security and penetration testing.
  • Perform scoping, vulnerability scanning and reconnaissance on a range of devices, platforms, protocols, systems and organisations.
  • Exploit vulnerabilities for a range of purposes, including access control, payload delivery and privilege escalation.

Professional Report - Preliminary

Assessment Type 1: Professional task
Indicative Time on Task 2: 28 hours
Due: 25/09/2026
Weighting: 30%
Groupwork/Individual: Individual
Short extension 3: No
AI Approach: Open

You will complete various activities, recording your results in a journal. Drawing upon your journal as evidence, you will produce a professional report written in a form that is suitable for submission to a client for review by both executive and technical audiences.


On successful completion you will be able to:
  • Explain the importance of ethics and ethical behaviour in relation to offensive security and penetration testing.
  • Perform scoping, vulnerability scanning and reconnaissance on a range of devices, platforms, protocols, systems and organisations.
  • Exploit vulnerabilities for a range of purposes, including access control, payload delivery and privilege escalation.
  • Effectively communicate results to technical and non-technical audiences.
  • Demonstrate the keeping and maintaining of an accurate and reflective record of activities undertaken as part of professional practice. 

Professional Report - Supplementary

Assessment Type 1: Professional task
Indicative Time on Task 2: 38 hours
Due: 13/11/2026
Weighting: 40%
Groupwork/Individual: Individual
Short extension 3: No
AI Approach: Open

You will complete various activities, recording your results in a journal. Drawing upon your journal as evidence, you will produce a professional report written in a form that is suitable for submission to a client for review by both executive and technical audiences.


On successful completion you will be able to:
  • Explain the importance of ethics and ethical behaviour in relation to offensive security and penetration testing.
  • Perform scoping, vulnerability scanning and reconnaissance on a range of devices, platforms, protocols, systems and organisations.
  • Exploit vulnerabilities for a range of purposes, including access control, payload delivery and privilege escalation.
  • Effectively communicate results to technical and non-technical audiences.
  • Demonstrate the keeping and maintaining of an accurate and reflective record of activities undertaken as part of professional practice. 

1 If you need help with your assignment, please contact:

  • the academic teaching staff in your unit for guidance in understanding or completing this type of assessment
  • Academic Success for academic skills support.

2 Indicative time-on-task is an estimate of the time required for completion of the assessment task and is subject to individual variation.

3 An automatic short extension is available for some assessments. Apply through the Service Connect Portal.

Delivery and Resources

Week 1

Each week you should participate in your scheduled two hour practical workshop. For details of scheduled classes consult the timetables webpage.

Note that lectures commence in week 1, and workshops commence in week 2. The week-by-week details of the workshop activities will be available from iLearn.

Textbook and Reading Materials

COMP3330 is a practice-oriented unit and as such the practical exercises and lecture notes make up the bulk of the learning material. Additional reading materials will be provided on iLearn as required.

Unit Websites

COMP3330 is administered via iLearn (http://ilearn.mq.edu.au/).

Lecture Recordings

Digital recordings of lectures may be available. They will be linked from iLearn.

Technologies Used and Required

COMP3330 is a BYOD (Bring Your Own Device) unit. You will be expected to bring your own laptop computer (Windows or Mac) to the workshop, install and configure the required software, and incorporate secure practices into your daily work (and play!) routines. The laptop must be capable of running a Kali virtual machine. At a minimum your laptop should have 120GB of free disk space, 8GB of memory, and 4 CPU cores.

General Notes

In this unit, you should do the following:

  • Review recorded lecture materials.
  • Participate your weekly workshop session.
    • Many activities in the unit are group based and you will be expected to collaborate effectively with your group members.
  • Work on any assignments that have been released.

Note that Workshops commence in week 2.

Communication Methods in COMP3330 

All announcements about unit-related matters will be communicated through iLearn. It is the student's responsibility to ensure they check iLearn announcements, forums and FAQ sections regularly.

Students are encouraged to use the iLearn forums for asking questions about unit content and concepts. Where questions are about specific details in an assessment submission, this may need to be sent via the dedicated unit email address so as not to be at risk of breaching the university academic integrity policy.

Students should use the appropriate iLearn forms for contacting staff. There may be occasions where unit staff will email a student directly to their @students.mq.edu.au email address. It is the student's responsibility to ensure they check their official university email regularly for communications from the university staff.

Policies and Procedures

Macquarie University policies and procedures are accessible from Policy Central (https://policies.mq.edu.au). Students should be aware of the following policies in particular with regard to Learning and Teaching:

Students seeking more policy resources can visit Student Policies (https://students.mq.edu.au/support/study/policies). It is your one-stop-shop for the key policies you need to know about throughout your undergraduate student journey.

To find other policies relating to Teaching and Learning, visit Policy Central (https://policies.mq.edu.au) and use the search tool.

Student Code of Conduct

Macquarie University students have a responsibility to be familiar with the Student Code of Conduct: https://students.mq.edu.au/admin/other-resources/student-conduct

Results

Results published on platform other than eStudent, (eg. iLearn, Coursera etc.) or released directly by your Unit Convenor, are not confirmed as they are subject to final approval by the University. Once approved, final results will be sent to your student email address and will be made available in eStudent. For more information visit connect.mq.edu.au or if you are a Global MBA student contact globalmba.support@mq.edu.au

Academic Integrity

At Macquarie, we believe academic integrity – honesty, respect, trust, responsibility, fairness and courage – is at the core of learning, teaching and research. We recognise that meeting the expectations required to complete your assessments can be challenging. So, we offer you a range of resources and services to help you reach your potential, including free online writing and maths support, academic skills development and wellbeing consultations.

Student Support

Macquarie University provides a range of support services for students. For details, visit http://students.mq.edu.au/support/

Academic Success

Academic Success provides resources to develop your English language proficiency, academic writing, and communication skills.

The Library provides online and face to face support to help you find and use relevant information resources. 

Student Services and Support

Macquarie University offers a range of Student Support Services including:

Student Enquiries

Got a question? Ask us via the Service Connect Portal, or contact Service Connect.

IT Help

For help with University computer systems and technology, visit https://students.mq.edu.au/support/technology/service-desk

When using the University's IT, you must adhere to the Acceptable Use of IT Resources Policy. The policy applies to all who connect to the MQ network including students.

Changes from Previous Offering

This is the first offering of this unit, however we value student feedback to be able to continually improve the way we offer our units. As such we encourage students to provide constructive feedback via student surveys, to the teaching staff directly, or via the FSE Student Experience & Feedback link in the iLearn page.

Changes since First Published

Date Description
20/07/2026 Change to reflect updated staffing allocation.

Unit information based on version 2026.04 of the Handbook