EC-Council Certified Security Analyst (Practical)

ECSA (Practical)

About the EC-Council Certified Security Analyst (Practical)

ECSA (Practical) is a 12-hour, rigorous practical exam built to test your penetration testing skills.

ECSA (Practical) presents you with an organization and its network environment, containing multiple hosts. The internal network consists of several subnets housing various organizational units. It is made up of militarized and demilitarized zones, connected with a huge pool of database servers in a database zone. As a security precaution, and by design, all the internal resource zones are confi­gured with different subnet IPs. The militarized zone houses the domain controllers and application servers that provide application frameworks for various departments of the organization.

The candidates are required to demonstrate the application of the penetration testing methodology that is presented in the ECSA program, and are required to perform a comprehensive security audit of an organization, just like in the real world. You will start with challenges requiring you to perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch, and post exploitation maneuvers.

EC-Council Certified Security Analyst (Practical)

The ECSA (Practical) tests your ability to perform threat and exploit research, understand exploits in the wild, write your own exploits, customize payloads, and make critical decisions at different phases of a pen testing engagement that can make or break the whole assessment. You will also be required to create a professional pen testing report with essential elements and guidance for the organization in the scenario to act on.

ECSA (Practical) Credential Holders Are Proven To Be Able To:

  • Perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch and post exploitation maneuvers.
  • Customize payloads
  • Make critical decisions at different phases of a pen-testing engagement
  • Perform advanced network scans beyond perimeter defenses
  • Perform automated and manual vulnerability analysis
  • Customization, launch, and post exploitation maneuvers
  • Perform a full fledged Penetration Testing engagement
  • Create a professional pen-testing report
  • Demonstrate the application of penetration testing methodology presented in the ECSA program

ECSA (Practical) Training Program: Penetration Testing

The preparatory course for this certification is the EC-Council Certified Security Analyst (ECSA) course. While there is no additional course or training required after the ECSA, we strongly recommend that you attempt the ECSA (Practical) exam only if you have attended the current ECSA course/equivalent. The aim of this credential is to help set gifted penetration testing practitioners apart from the crowd.

Who Is It For?
  • Ethical Hackers
  • Penetration Testers
  • Network server administrators
  • Firewall Administrators
  • Security Testers
  • System Administrators and Risk Assessment professionals
Eligibility Criteria

There is no predefined eligibility criteria for those interested in attempting the LPT (Master) exam. You can purchase the exam dashboard code here.

Clause: Age Requirements and Policies Concerning Minors

The age requirement for attending the training or attempting the exam is restricted to any candidate that is at least 18 years old.

Application process

In order to proceed with the exam the below steps will need to be completed:

  • The exam dashboard code can be purchased here.
  • Upon successful purchase, the candidate will be sent the exam dashboard code with instructions to schedule the exam.

Note:The exam dashboard code is valid for 3 months from date of receipt.

  • Should you require the exam dashboard code validity to be extended, kindly contact before the expiry date. Only valid/ active codes can be extended.
  • The exam needs to be scheduled a min 3 days prior to the desired exam date. Exam slots are subject to availability.
Exam Sanctity

The trust that the industry places in our credentials is very important to us. We see it as our duty to ensure that the holders of this credential are proven, “hands on”, penetration testers who are able to perform in the real world to solve real world challenges.

As such, the ECSA (Practical) is designed as a hands-on exam that will test the skills of the penetration tester BEYOND just their knowledge.

This exam is an online, proctored, practical exam that can last up to 12 hours.

We know that travelling to an exam center can be difficult for many. As such, we are pleased to announce that you can take the ECSA (Practical) exam from the comfort of your home, but you need to be prepared to be proctored by a dedicated EC-Council Proctor certification team under strict supervision.

Training Options
iLearn (Self-Study)

This solution is an asynchronous, self-study environment which delivers EC-Council’s sought after IT Security training courses in a streaming video format.

iWeek (Live Online)

This solution is a live, online, instructor-led training course which means you can attend a course with a live instructor from anywhere with an internet connection.

Master Class

This solution offers you the opportunity to learn from world-class instructors and the opportunity to collaborate with top Infosecurity professionals.

Training Partner (In Person)

This solution offers “in-person” training so that you can get the benefit of collaborating with your peers and gaining real-world skills, conveniently located in your backyard.

Need Training?

EC-Council’s Official delivery platform includes your study material, iLabs (virtual labs) and gives you the most flexible options for training to fit your busy work schedule!

Learn More about Training Options


1. What will I receive as part of my purchase towards the ECSA (Practical) exam?

You will receive an Aspen Dashboard access code with instructions as part of your purchase towards the ECSA (Practical) exam.

2. For how long is the Aspen Dashboard access code valid for?

The Aspen Dashboard access code is valid for 3 months from the date of receipt.

3. For how long is the Aspen Dashboard access valid for?

The Aspen Dashboard access is valid for 15 days from the day it is unlocked using a valid key.

4. What does the Dashboard consist of?

The Dashboard consists of:

  • Detailed Instruction guide
  • Exam scheduling service
  • Exam launching service
  • Exam progress tracking
  • Sample report templates
  • Report submission
  • Status of report

5. What is the structure of the exam?

The candidate is required to complete the pen-testing challenge and submit their pen-testing report to complete the exam.

6. What is the duration of the exam?

The exam challenge is a 12-hour session.

7. What is the passing criteria for the exam?

The candidate needs to complete a minimum of 5 out of the 8 challenges successfully in order to pass the ECSA (Practical) Exam.

8. How much notice is required to book the exam session?

Sessions should be booked at least 3 days in advance of the desired exam date.

Note: All exam sessions are proctored by EC-Council Certification department.

9. What are the important things to keep in mind before I schedule my exam?

Once you are ready to proceed with your exam, please ensure you understand the below:

  • Cancellation requests are to be made 24 hours in advance.
  • Rescheduling is possible 72 hours prior to the exam session
  • Candidate has a grace period of 15 minutes to show up for the exam session.
  • After 3 no-show cases, the candidate will be required to seek special permission from the Director – Certification to proceed with their attempt.

10. What is the retake policy?

Retake exam requests can only be purchased by writing to, should a candidate fail the exam. Note: The challenges as well as the report are required to be submitted within the 15 days window. This includes re-attempts if any.

11. Can the report submission be extended?

Report submission can be extended for 7 days only, by paying $100 as long as the dashboard is active

Note: Should the dashboard expire the candidate will need to purchase a new kit for $600. (This applies even if the candidate has passed the exam challenge)

12. Is the ECSA (Practical) a part of the EC-Council Continuing Education Scheme?

Yes, the ECSA (Practical) is a part of the EC-Council Continuing Education Scheme.