D484 Penetration Testing carries banner number ITAS 5223 and is worth 4 competency units. It covers penetration testing and vulnerability management across planning and scoping, information gathering, vulnerability identification, and exploits. D484 and ITAS 5223 are one requirement, and it is the graduate counterpart to the bachelor's D332. At graduate level the emphasis moves toward the programme around testing: why it happens, how often, and what the organization does with the output.
Testing is one input to vulnerability management
A single penetration test produces a snapshot. An organization that only commissions tests, and does nothing between them, is measuring itself once a year and behaving unmanaged for the other fifty-one weeks. The graduate framing of this course is that testing sits inside a continuous programme: assets are inventoried, weaknesses are discovered continuously, findings are triaged against real exposure, remediation is tracked to closure, and testing validates that the whole cycle works.
Scoping remains the professional foundation. Written authorisation, defined boundaries, agreed rules of engagement, testing windows, escalation contacts and handling of any sensitive data encountered are what separate authorised testing from an offence. At graduate level you are also expected to reason about scope as a risk decision: what a narrow scope fails to test, and what a broad one costs.
Threat modelling of the engagement is the addition that distinguishes graduate work. Rather than running a standard sequence, you decide what an attacker who wanted this organization's crown jewels would plausibly attempt, and design the test to answer that question. A test that mirrors credible adversary behaviour tells an executive something useful; a test that enumerates every service tells them how many services they have.
Reporting carries proportionally more weight here too. The graduate reader is a decision maker, and a report that cannot express business consequence and cannot be actioned by an operations team has failed even if the technical work was excellent.
Your result reads Competent or Not Competent, and neither letter grades nor an ordinary grade point average are recorded, and the 4 competency units measure course size within a six month term sold at one price. All practical work happens inside the authorised environment your course provides, never against systems you lack written permission to test.
Turning aspects into a test programme document
If your version of D484 uses a performance assessment, expect aspects covering the engagement lifecycle plus the management wrapper around it. WGU requires a score of 2 in each aspect for a task to pass and judges each aspect alone, so strong findings will not carry an unaddressed vulnerability management or reporting aspect.
Budget before drafting. Take a rubric with eight scored aspects and a target near 2,500 words alongside your evidence. Reserve 160 words for the engagement context and authorisation, and 120 for the close, leaving 2,220 across eight aspects, or roughly 277 each. Weight by demand: three aspects requiring analysis and recommendation take 380 each, which is 1,140; the five remaining aspects, covering scoping, methodology, discovery, findings format and remediation tracking, take 216 each, which is 1,080. Together that is 2,220.
Write findings to a fixed template and repeat it without variation: what was found, where, how it was verified, what an attacker gains, the likelihood in this environment, the fix, and who would own the fix. That last element is the graduate addition and it is what makes a report actionable rather than informative.
Reserve budget for the programme layer. How often should testing recur, what triggers an out-of-cycle test, how are findings tracked between engagements, and what measure tells the organization whether it is improving are the questions that separate this course from its undergraduate counterpart.
Shape for a graduate testing report
D484 deliverables usually produce a report plus programme recommendations. These proportions fit that document.
| Section | Content | Share |
|---|---|---|
| Engagement and authorisation | Objective, scope, exclusions, rules of engagement, window and the written authority relied on. | 12 percent |
| Threat model | The adversary the test simulates, their likely objectives, and why that model fits this organization. | 14 percent |
| Methodology | Approach and tooling, described so another tester could repeat the engagement. | 11 percent |
| Discovery and findings | What exists, and each validated weakness in the fixed template with evidence. | 24 percent |
| Business impact | What each finding means in terms the executive reader already cares about. | 15 percent |
| Remediation and ownership | Specific fixes, effort, owner and operational side effects of applying them. | 14 percent |
| Programme recommendations | Testing cadence, triggers, tracking between engagements and the improvement measure. | 10 percent |
Evidence, honesty and the authorisation line
Findings must be verified before they are reported. Scanner output is a candidate list, and reproducing it as findings is the fastest way to lose credibility with both an evaluator and a client. Show the interaction, the response and the timestamp for each confirmed weakness, cropped to what matters and labelled with what it proves.
For citations, methodology belongs to published testing standards and guides, weakness classifications to the recognised public catalogues, and product behaviour to vendor documentation. Where you assign severity, name the scoring system and then state why the environment-specific impact differs from the generic score, because that adjustment is the analytical work graduate marking is looking for.
Two boundaries are absolute and apply to your study as much as to professional work. Test only what your course environment authorises, and never systems belonging to an employer, a family member or any third party without explicit written permission. And report only what you verified, keeping unconfirmed material clearly labelled and separate.
Our own boundary is the same shape. We teach method, review your reasoning and help you structure the report; we do not run tests, we do not touch any system, and we never ask for or handle credentials of any kind, yours or an organization's.
Use the citation style your task names and put the citation where the assertion actually appears.
What earns Competent at graduate level
Competent reports establish authorisation, simulate a defensible threat model, verify every finding, express impact in business terms, assign ownership for remediation, and end with a programme that keeps working after the engagement closes.
Returns follow four shapes. The report is a technical findings list with no business framing. Severity is copied from a generic score with no environmental adjustment. The threat model is absent, so the methodology looks like a checklist rather than a designed test. Or the programme layer is missing entirely, which at graduate level is the difference between this course and the undergraduate one.
Two habits close most of the remaining distance. The first is writing the executive summary last and treating it as a separate document with its own audience: three or four paragraphs, no jargon, the shape of the risk and the two things to do about it. The second is separating findings by whether they are configuration errors, missing controls or design weaknesses, because those three categories go to different teams, cost different amounts and carry different timescales. A report organised that way turns into a work plan without anyone having to reorganise it.
A useful check: give your executive summary to someone with no security background and ask what they would spend money on. If they cannot answer, the impact section is not doing its job, and no amount of technical detail elsewhere will fix that.
Revision and resubmission carry no grade consequence at WGU, so send it in the moment each aspect is genuinely addressed, and treat the first submission as a way of buying exact feedback. If your section also carries an objective assessment, WGU objective assessments are proctored and our position does not move: preparation only, with methodology drills, report structure practice and a candid read on your preassessment result. Nobody here sits an assessment, take no part once one begins, and we neither ask for nor accept portal credentials.
Findings solid, report not executive-ready?
Send the D484 rubric and your evidence. We build the threat model, the finding template and the programme layer, with word targets per aspect.
Eight mistakes that cost time in D484
- No threat model. A designed test answers a question. An undesigned one enumerates services.
- Unverified findings. Confirm everything before it enters the findings section. Candidates belong in an appendix.
- Generic severity. Adjust for this environment and show the reasoning. That adjustment is the graduate work.
- No business impact. The reader decides budgets. Tell them what a finding means in their terms.
- Remediation with no owner. A fix nobody owns does not get applied, and the report knows it.
- Missing programme layer. Cadence, triggers, tracking and an improvement measure are what make testing continuous.
- Scope treated as formality. At graduate level scope is a risk decision with stated consequences.
- Testing beyond authorisation. Never, in coursework or anywhere else. Written permission defines the boundary.
Three questions students ask about D484
How does D484 differ from the bachelor's D332?
Do I need offensive security certifications first?
What tooling should I use?
Where D484 sits in WGU's programs
The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.