Skip to main content
Aegentra
Guide · Updated

Ethical Hacking Certification in Australia: The PECB Lead Ethical Hacker Guide

A practical guide to the PECB Certified Lead Ethical Hacker (CLEH) — the 5-day, hands-on penetration-testing certification for professionals in Australia. This guide covers what the course teaches, the 6-hour practical exam, the PTES and OSSTMM methodologies behind it, real AUD cost, and how to get certified. Written for aspiring and working penetration testers, red-teamers, and security engineers who want to prove they can lawfully break into systems — and report it properly.
By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra9 min readLast reviewed

What is the PECB Certified Lead Ethical Hacker?

The PECB Certified Lead Ethical Hacker (CLEH) is a 5-day, hands-on penetration-testing certification. It teaches the methods and tools ethical hackers use to lawfully assess the security of systems, discover their vulnerabilities, and report them so they can be fixed. The course is built on the principle of practising what you learn — it runs on live lab sessions across reconnaissance, exploitation, privilege escalation, pivoting, and reporting, using Kali Linux throughout.

Unlike awareness-level qualifications, CLEH is designed to prove capability. By the end you should be able to plan, manage, and perform an information-security penetration test end to end — from scoping and the contractual agreement, through active exploitation, to a written report a client can act on.

Why penetration-testing skills matter in Australia

Security testing may support control assurance and buyer requirements. Its scope and frequency should follow the actual risk, obligation and contract:

  • The SOCI Act — testing obligations depend on the asset, entity and applicable requirements. Do not infer a universal penetration-test or training mandate for every operator.
  • The ASD Essential Eight — maturity uplift programs increasingly pair control implementation with regular testing to prove the controls actually hold.
  • APRA CPS 234 — regulated entities must test security controls systematically and after material change.
  • Customer assurance — some vendor security questionnaires may request evidence of periodic penetration testing; check each buyer’s current requirements.

The credential may support progression into security testing and consulting roles. Actual eligibility, remuneration and engagement requirements depend on experience, sector, location and employer or client requirements.

Who should take this course

  • Aspiring penetration testers who want to learn the core techniques used on real engagements
  • Security professionals moving into offensive security or red-team roles
  • Information-security officers and cybersecurity professionals responsible for system security
  • Security team members who want to understand attacks well enough to defend against them
  • Managers and advisors who need to scope, manage, or oversee ethical-hacking activities
  • Technical experts who want to plan and perform a penetration test properly
Day one sets up the standards and scoping, then reconnaissance, exploitation, and post-exploitation and reporting take days two to four — with the exam held back to day five.

What you learn — the 5-day agenda

The course is four days of hands-on training plus the certification exam on day five:

Day 1Introduction to ethical hacking

Testing standards and frameworks (PTES, OSSTMM), fundamental concepts, network and cryptography foundations, Kali Linux, initiating the test, scoping, and the legal and contractual side of an engagement.

Day 2Reconnaissance

Passive and active reconnaissance and the identification of vulnerabilities — the information-gathering phase that shapes everything that follows.

Day 3Exploitation

Threat modelling and attack planning, evading intrusion detection, server-side, client-side, and web-application attacks, Wi-Fi attacks, privilege escalation, pivoting, file transfers, and maintaining access.

Day 4Post-exploitation and reporting

Cleaning up and destroying artefacts, generating a findings report, and writing recommendations that let a client actually remediate.

Day 5Certification exam

The 6-hour hands-on practical exam (see below).

You have to actually compromise at least two target machines, and because it is open-book your course notes come into the exam with you.

The exam: a 6-hour hands-on practical

The CLEH exam is what sets the credential apart. It is a 6-hour, open-book, two-part exam:

  • A practical exam — you must compromise at least two target machines through penetration testing.
  • A written report — you document the process, findings, and remediation advice, exactly as you would for a real client.

Because it is open-book, you can use the course materials and your own notes throughout — the exam rewards genuine skill and a repeatable process, not memorisation. It covers six competency domains: information gathering; threat modelling and vulnerability identification; exploitation techniques; privilege escalation; pivoting and file transfers; and reporting.

The exam voucher and one free resit (within 12 months) are included in the course price, so a first attempt and one retake are covered.

The methodology: PTES and OSSTMM

A good penetration test is repeatable and defensible, not a bag of tricks. CLEH is structured around two recognised, vendor-neutral methodologies:

  • PTES (Penetration Testing Execution Standard) — a seven-phase model from pre-engagement and intelligence gathering through exploitation, post-exploitation, and reporting.
  • OSSTMM (Open Source Security Testing Methodology Manual) — a measurable, metrics-driven approach to operational security testing.

Learning the work through these frameworks means your engagements have a consistent shape a client — or an auditor — can trust, and your reports map to expectations the wider industry already recognises.

Cost and what is included

Through Aegentra, an official PECB authorised training partner, the PECB Certified Lead Ethical Hacker course is $1,165 + GST. The published package includes the following items; PECB application and credential requirements still apply:

  • 450+ pages of official PECB course materials
  • Hands-on lab sessions and practical examples
  • The official PECB CLEH exam voucher
  • One free exam resit within 12 months
  • 35 CPD credits on completion
  • 12 months access via myPECB

This course publishes 12 months of material access. Course-material access, examination and retake deadlines, and any certificate-application deadline are separate. Confirm the material-access start date in your booking confirmation and check the deadlines recorded in myPECB before scheduling your examination. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply.

Online training formats and booking arrangements are listed on the course page; an enquiry does not confirm live-training availability.

Passing the exam is not the last step — the full credential also requires two years of penetration-testing and cybersecurity experience.

How to enrol and get certified

The path from purchase to credential is straightforward:

1Enrol through the published checkout and retain the order confirmation and tax invoice. Course provisioning and examination booking are separate steps.
2Create your PECB account using the same email, so we can link the course to your myPECB profile.
3Work through the materials and labs at your own pace over 12 months; use the public schedule only if a confirmed cohort is shown.
4Sit the 6-hour practical exam, compromise your targets, and submit your report.
5On passing, apply for the PECB Certified Lead Ethical Hacker credential (two years of penetration-testing experience is required for the full credential).

Ready to start? View the full course details and enrol, or browse the whole Aegentra Academy catalogue.

Primary references and applicability

These sources explain the requirements and scope distinctions discussed above. Check their applicability to the organisation or credential.

FAQs

What is the PECB Certified Lead Ethical Hacker (CLEH)?

CLEH is a 5-day, hands-on penetration-testing certification from PECB. It teaches the methods and tools ethical hackers use to lawfully assess systems, discover vulnerabilities, and report them — reconnaissance, exploitation, privilege escalation, pivoting, and reporting — using Kali Linux and industry methodologies. The credential assesses relevant capability; each engagement still requires written authorisation, agreed scope and appropriate experience.

Is the Lead Ethical Hacker exam practical or multiple-choice?

Open-book, hands-on practical + report writing. Duration: 6 hours. Two parts — a practical exam (compromise at least two target machines through penetration testing) and a written findings report. Covers six competency domains: information gathering; threat modelling and vulnerability identification; exploitation techniques; privilege escalation; pivoting and file transfers; and reporting. Passing requirements: Practical — compromise ≥2 targets and pass the report. Check the current PECB examination record and assigned examination before booking.

Do I need prior experience to take the course?

PECB expects information-security knowledge and advanced operating-system skills. Networking and programming knowledge are recommended. The credential has a separate professional-experience requirement.

How much does the Lead Ethical Hacker course cost in Australia?

Self-Study: A$ 1,165.00 excluding GST (A$ 1,281.50 including Australian GST). Published inclusions (subject to the credential and retake clarification immediately below): 450+ pages of comprehensive training materials; Hands-on lab sessions and practical examples; 12 months access via myPECB; Official PECB CLEH exam voucher; 6-hour practical exam + report (open book); Two attempts (initial + one free resit within 12 months); PECB digital certificate on pass; 35 CPD credits on completion; PTES and OSSTMM-aligned methodology; Kali Linux hands-on practice; Aegentra Academy support inbox. Clarification: references to a credential or certificate on pass do not mean automatic award. The eligible PECB credential requires an application and PECB approval, including applicable experience and ethics requirements. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply. A retained inclusion referring to the initial examination date does not extend or restart this policy cycle. Australian GST follows the billing address. Check the course page for the full inclusions and current booking options.

Which methodologies does the course follow?

The course is built around recognised, vendor-neutral penetration-testing methodologies — the Penetration Testing Execution Standard (PTES) and the Open Source Security Testing Methodology Manual (OSSTMM). These give you a repeatable, defensible process for scoping, executing, and reporting a test, rather than an ad-hoc collection of tricks.

Is the credential recognised in Australia and internationally?

Accreditation varies by credential. PECB publishes personnel-certification accreditation under applicable ISO/IEC 17024 scopes and ANAB certificate-program accreditation under ANSI/ASTM E2659-24 for specified programs. Verify the applicable published PECB scope.

How long does it take, and how is it delivered?

It is a 5-day course equivalent — four days of hands-on training content followed by the certification exam on day five. The published option is self-paced online through myPECB. Current online training formats and booking arrangements are listed on the course page; an enquiry does not confirm live-training availability.

What jobs does ethical-hacking certification support?

Penetration tester, security consultant, red-team operator, application security engineer, and SOC roles that need offensive skills. In Australia, demand is driven by the SOCI Act, the ASD Essential Eight, APRA CPS 234, and enterprise procurement that increasingly asks vendors to demonstrate regular penetration testing.

PECB Certified Lead Ethical Hacker

Ready to become a certified ethical hacker?

The 5-day PECB Certified Lead Ethical Hacker course — hands-on labs, a 6-hour practical exam, and the official exam voucher included. Study online; check the course page for current formats and booking arrangements.