EC-Council Certified Security Analyst (Practical)
Certified Ethical Hacker

EC-Council Certified Security Analyst (Practical)

About the EC-Council Certified Security Analyst (Practical)

ECSA (Practical) is a 12-hour, rigorous practical exam built to test your penetration testing skills.

ECSA (Practical) presents you with an organization and its network environment, containing multiple hosts. The internal network consists of several subnets housing various organizational units. It is made up of militarized and demilitarized zones, connected with a huge pool of database servers in a database zone. As a security precaution, and by design, all the internal resource zones are confi­gured with different subnet IPs. The militarized zone houses the domain controllers and application servers that provide application frameworks for various departments of the organization.

The candidates are required to demonstrate the application of the penetration testing methodology that is presented in the ECSA program, and are required to perform a comprehensive security audit of an organization, just like in the real world. You will start with challenges requiring you to perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch, and post exploitation maneuvers.

The World’s First Penetration Testing Industry Readiness Assessment That Is 100% Verified, Online, Live, Proctored!


The ECSA (Practical) tests your ability to perform threat and exploit research, understand exploits in the wild, write your own exploits, customize payloads, and make critical decisions at different phases of a pen testing engagement that can make or break the whole assessment. You will also be required to create a professional pen testing report with essential elements and guidance for the organization in the scenario to act on.

ECSA (Practical) Credential Holders Are Proven To Be Able To:

  • Perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch and post exploitation maneuvers.
  • Customize payloads
  • Make critical decisions at different phases of a pen-testing engagement
  • Perform advanced network scans beyond perimeter defenses
  • Perform automated and manual vulnerability analysis
  • Customization, launch, and post exploitation maneuvers
  • Perform a full fledged Penetration Testing engagement
  • Create a professional pen-testing report
  • Demonstrate the application of penetration testing methodology presented in the ECSA program

ECSA (Practical) Training Program: Penetration Testing

The preparatory course for this certification is the EC-Council Certified Security Analyst (ECSA) course. While there is no additional course or training required after the ECSA, we strongly recommend that you attempt the ECSA (Practical) exam only if you have attended the current ECSA course/equivalent. The aim of this credential is to help set gifted penetration testing practitioners apart from the crowd.

Who Is It For?

  • Ethical Hackers
  • Penetration Testers
  • Network server administrators
  • Firewall Administrators
  • Security Testers
  • System Administrators and Risk Assessment professionals

Eligibility Criteria

There is no predefined eligibility criteria for those interested in attempting the ECSA (Practical) exam. You can purchase the exam dashboard code here

Clause: Age Requirements and Policies Concerning Minors

The age requirement for attending the training or attempting the exam is restricted to any candidate that is at least 18 years old.

If the candidate is under the age of 18, they are not eligible to attend the official training or eligible to attempt the certification exam unless they provide the accredited training center/EC-Council a written consent of their parent/legal guardian and a supporting letter from their institution of higher learning. Only applicants from nationally accredited institution of higher learning shall be considered.

Disclaimer:

EC-Council reserves the right to impose additional restriction to comply with the policy. Failure to act in accordance with this clause shall render the authorized training center in violation of their agreement with EC-Council.

EC-Council reserves the right to revoke the certification of any person in breach of this requirement.

Application Process

In order to proceed with the exam the below steps will need to be completed:

  • The exam dashboard code can be purchased here.
  • Upon successful purchase, the candidate will be sent the exam dashboard code with instructions to schedule the exam.

Note:The exam dashboard code is valid for 1 year from date of receipt.

  • Should you require the exam dashboard code validity to be extended, kindly contact [email protected] before the expiry date. Only valid/ active codes can be extended.
  • The exam needs to be scheduled a min 3 days prior to the desired exam date. Exam slots are subject to availability.

Exam Sanctity

The trust that the industry places in our credentials is very important to us. We see it as our duty to ensure that the holders of this credential are proven, “hands on”, penetration testers who are able to perform in the real world to solve real world challenges.

As such, the ECSA (Practical) is designed as a hands-on exam that will test the skills of the penetration tester BEYOND just their knowledge.

This exam is an online, proctored, practical exam that can last up to 12 hours.

We know that travelling to an exam center can be difficult for many. As such, we are pleased to announce that you can take the ECSA (Practical) exam from the comfort of your home, but you need to be prepared to be proctored by a dedicated EC-Council Proctor certification team under strict supervision.

FAQs:


1. What will I receive as part of my purchase towards the ECSA (Practical) exam?
A.

You will receive an Aspen Dashboard access code with instructions as part of your purchase towards the ECSA (Practical) exam.

2. For how long is the Aspen Dashboard access code valid for?
A.

The Aspen Dashboard access code is valid for 3 months from the date of receipt.

3. For how long is the Aspen Dashboard access valid for?
A.

The Aspen Dashboard access is valid for 15 days from the day it is unlocked using a valid key.

4. Does EC-Council consider special accommodation?
A.

The Dashboard consists of:

  • Detailed Instruction guide
  • Exam scheduling service
  • Exam launching service
  • Exam progress tracking
  • Sample report templates
  • Report submission
  • Status of report
5. What is the structure of the exam?
A.

The candidate is required to complete the pen-testing challenge and submit their pen-testing report to complete the exam.

6. What is the duration of the exam?
A.

The Exam challenge is a 12 hour session.

7. What is the passing criteria for the exam?
A.

The candidate needs to complete a minimum of 5 out of the 8 challenges successfully in order to pass the ECSA (Practical) Exam.

8. How much notice is required to book the exam session?
A.

Sessions should be booked at least 3 days in advance of the desired exam date.

Note: All exam sessions are proctored by EC-Council Certification department.

9. What are the important things to keep in mind before I schedule my exam?
A.
  • Cancellation requests are to be made 24 hours in advance.
  • Rescheduling is possible 72 hours prior to the exam session
  • Candidate has a grace period of 15 minutes to show up for the exam session.
  • After 3 no-show cases, the candidate will be required to seek special permission from the Director - Certification to proceed with their attempt.
  • FAQs on exam proctoring will be available here.
10. Where can I purchase the ECSA (Practical) exam voucher?
A.

The exam voucher can be purchased here.

Note: The challenges as well as the report are required to be submitted within the 15 days window. This includes re-attempts if any.

11. What is the retake policy?
A.

Retake exam requests can only be purchased by writing to [email protected], should a candidate fail the exam.

Note: The challenges as well as the report are required to be submitted within the 15 days window. This includes re-attempts if any.

12. Can the report submission be extended?
A.

Report submission can be extended for 7 days only, by paying $100 as long as the dashboard is active.

Note: Should the dashboard expire the candidate will need to purchase a new kit for $600. (This applies even if the candidate has passed the exam challenge)

13. Is the ECSA (Practical) a part of the EC-Council Continuing Education Scheme?
A.

Yes, the ECSA (Practical) is a part of the EC-Council Continuing Education Scheme.