Technology
Professional Diploma in Cyber Security and Ethical Hacking
විෂය නිර්දේශය · Syllabus
Full 24-week curriculum
This 24-week, 100% online curriculum is designed specifically for absolute beginners. Starting with the absolute basics of how computers and networks operate, the syllabus progressively builds the technical, analytical, and offensive skills required to secure digital environments. Upon graduation, students will possess a robust technical portfolio, qualifying them to directly enter a Bachelor of Science (BSc) program in Cyber Security, Ethical Hacking, or Computer Science. The course is strictly practical and project-based. There are absolutely no written exams. All assessments are evaluated through digital penetration testing reports, forensic logs, and technical security blueprints submitted online.
Module 1 · Weeks 1-4
Cyber Security Fundamentals & The Hacking Lab
Understanding the core principles of information security and setting up a safe environment for hacking.
- Week 1The CIA Triad & Threat Landscape: Understanding Confidentiality, Integrity, and Availability. Identifying common threat actors (script kiddies, APTs, hacktivists) and their motives.
- Week 2Networking for Hackers: A crash course in how data travels. Understanding IP addresses, MAC addresses, ports, TCP/UDP protocols, and the OSI model.
- Week 3Setting Up the Virtual Lab: Installing virtualization software (VirtualBox/VMware) and deploying Kali Linux. Understanding how to build a safe, isolated sandbox for testing malware and exploits.
- Week 4Introduction to the Linux Command Line: Navigating directories, managing file permissions, and mastering the essential terminal commands used by penetration testers.
Module 2 · Weeks 5-8
Defensive Security & Cryptography
Learning how systems are secured so that vulnerabilities can be properly identified and exploited later.
- Week 5Windows & Linux System Hardening: Understanding user privilege management, disabling unnecessary services, and securing the Windows Registry and Linux SSH configurations.
- Week 6Firewalls & Intrusion Detection Systems (IDS): How firewalls filter traffic. An introduction to setting up basic rules and understanding how IDS platforms (like Snort) detect suspicious activity.
- Week 7Cryptography Basics: Understanding symmetric vs. asymmetric encryption, hashing (MD5, SHA-256), and digital signatures. How data is protected at rest and in transit.
- Week 8Identity & Access Management (IAM): The fundamentals of password security, multi-factor authentication (MFA), and an introduction to Active Directory vulnerabilities.
Module 3 · Weeks 9-12
Ethical Hacking & Penetration Testing
Learning the structured phases of a cyber attack and utilizing industry-standard offensive tools.
- Week 9Reconnaissance & OSINT: Information gathering. Using tools like Maltego, Shodan, and Google Dorks to find publicly available data, exposed employee emails, and forgotten servers.
- Week 10Network Scanning & Enumeration: Using Nmap to discover live hosts, open ports, and running services on a target network without triggering alarms.
- Week 11Vulnerability Analysis: Using automated scanners (like Nessus or OpenVAS) to identify unpatched software and misconfigurations, and learning how to verify false positives.
- Week 12Exploitation (The Metasploit Framework): Taking control. Using Metasploit to launch exploits against identified vulnerabilities, gaining remote access to a target machine.
Module 4 · Weeks 13-16
Web Application Security & Exploitation
Hacking websites and web servers, focusing on the most common internet vulnerabilities.
- Week 13Web Architecture & HTTP: Understanding how web servers, databases, and browsers communicate. Intercepting web traffic using proxy tools like Burp Suite.
- Week 14The OWASP Top 10 (Part 1): Identifying and exploiting Injection flaws (SQL Injection) to extract sensitive data from backend databases.
- Week 15The OWASP Top 10 (Part 2): Understanding Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and broken authentication mechanisms.
- Week 16Web App Vulnerability Remediation: How to communicate web vulnerabilities to software developers so they can properly sanitize inputs and patch the code.
Module 5 · Weeks 17-20
Incident Response & Digital Forensics
Discovering what hackers did, tracking their footprints, and containing the damage after a breach.
- Week 17Network Traffic Analysis: Using Wireshark to capture and analyze data packets. Learning how to spot the signatures of malware communication or data exfiltration.
- Week 18Malware Analysis Fundamentals: A beginner's approach to safely examining malicious files in a sandbox to understand how they infect systems and maintain persistence.
- Week 19The Incident Response Lifecycle: How a security operations center (SOC) detects a breach, isolates the infected machines, eradicates the threat, and recovers the data.
- Week 20Digital Forensics Basics: How to preserve digital evidence. Acquiring memory dumps and analyzing hard drive images to uncover deleted files and hidden attacker logs.
Module 6 · Weeks 21-24
Governance, Reporting & Capstone Preparation
Understanding the business side of cybersecurity and executing the final graduation project.
- Week 21Security Compliance & Ethics: Understanding the legal boundaries of ethical hacking. A brief overview of frameworks like ISO 27001, GDPR, and PCI-DSS.
- Week 22Professional Report Writing: Transitioning from a hacker to a consultant. How to write an executive summary for business leaders and a technical breakdown for IT teams.
- Week 23Capstone Execution: Dedicated 40-hour week to research, scan, exploit, and document the final enterprise security project.
- Week 24Final Documentation Assembly: Reviewing, formatting, and submitting the final Capstone package to the digital portal.
Final assessment
Capstone assignment
A comprehensive digital document (Technical Penetration Test or Security Blueprint) submitted directly to the Examination Council. No live presentation or written exam is required.
To graduate and prove readiness for a BSc degree, students will execute a comprehensive security engagement. The specific simulated corporate network, vulnerable web application, or incident response scenario will be determined by the Trident Campus Examination Council and lecturers prior to Month 6. Students must apply that assigned scenario to one of the following practical tracks:
Track A
The Red Team Engagement (Offensive)
Submit a professional "Penetration Testing Report." The student will be given access to a simulated corporate network. They must perform full reconnaissance, exploit vulnerabilities to gain access to the simulated domain controller, and submit a highly detailed report documenting the attack chain, the severity of the vulnerabilities, and actionable patching instructions.
Track B
The Blue Team Defense System (Defensive)
Submit a "Security Architecture & Hardening Blueprint." The student will receive a vulnerable, misconfigured network infrastructure. They must redesign the network securely, implement strict firewall rules, configure an intrusion detection system (IDS), and provide a digital manual explaining how the new architecture defends against modern cyber threats.
Track C
The Digital Forensics Investigation (DFIR)
Submit a "Forensic Investigation & Incident Report." The student will be provided with server logs, a memory dump, and network traffic files from a simulated cyber attack. They must analyze the evidence to reverse-engineer the attack, document exactly how the breach occurred, what data was compromised, and outline the containment strategy.
24-week accelerated pathway · 60 credits · assessed online without written examinations
Ready to enrol?
Submit an application of interest and our admissions team will contact you with current intake dates, entry requirements and fees.
