
EC-COUNCIL CERTIFIED SECURITY ANALYST (Practical)
The ECSA (Practical) tests your ability to perform threat and exploit research, understand exploits in the wild, write your own exploits, customize payloads, and make critical decisions at different phases of a pen testing engagement that can make or break the whole assessment.
Fill the form & get free demo session
Contact Us
About EC-Council Certified Security Analyst Practical
ECSA (Practical) is a 12-hour, rigorous practical exam built to test your penetration testing skills.
ECSA (Practical) presents you with an organization and its network environment, containing multiple hosts. The internal network consists of several subnets housing various organizational units. It is made up of militarized and demilitarized zones, connected with a huge pool of database servers in a database zone. As a security precaution, and by design, all the internal resource zones are confi¬gured with different subnet IPs. The militarized zone houses the domain controllers and application servers that provide application frameworks for various departments of the organization.
The candidates are required to demonstrate the application of the penetration testing methodology that is presented in the ECSA program, and are required to perform a comprehensive security audit of an organization, just like in the real world. You will start with challenges requiring you to perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch, and post exploitation maneuvers.
The ECSA (Practical) tests your ability to perform threat and exploit research, understand exploits in the wild, write your own exploits, customize payloads, and make critical decisions at different phases of a pen testing engagement that can make or break the whole assessment. You will also be required to create a professional pen testing report with essential elements and guidance for the organization in the scenario to act on.
The World’s First Penetration Testing Industry Readiness Assessment That Is 100% Verified, Online, Live, Proctored!
ECSA (Practical) Training Program: Penetration Testing
The preparatory course for this certification is the EC-Council Certified Security Analyst (ECSA) course. While there is no additional course or training required after the ECSA, we strongly recommend that you attempt the ECSA (Practical) exam only if you have attended the current ECSA course/equivalent. The aim of this credential is to help set gifted penetration testing practitioners apart from the crowd.
ECSA (Practical) Credential Holders Are Proven To Be Able To:
- Perform advanced network scans beyond perimeter defenses, leading to automated and manual vulnerability analysis, exploit selection, customization, launch and post exploitation maneuvers.
- Customize payloads
- Make critical decisions at different phases of a pen-testing engagement
- Perform advanced network scans beyond perimeter defenses
- Perform automated and manual vulnerability analysis
- Customization, launch, and post exploitation maneuvers
- Perform a full fledged Penetration Testing engagement
- Create a professional pen-testing report
- Demonstrate the application of penetration testing methodology presented in the ECSA program
Who Is It For?
- Ethical Hackers
- Penetration Testers
- Network server administrators
- Firewall Administrators
- Security Testers
- System Administrators and Risk Assessment professionals
Eligibility Criteria:
To be eligible to apply to sit for the ECSA (Practical) Exam, candidate must either:
- Be an ECSA member in good standing (Your USD 100 application fee will be waived)
- Have a minimum of 2 years working experience in InfoSec domain (You will need to pay USD 100 as a non-refundable application fee)
- Have any other industry equivalent certifications such as OSCP or GPEN cert (You will need to pay USD 100 as a non-refundable application fee)
Application Process
- Applicants must apply directly to EC-Council via the online web form Click Here
- If further information is requested from the applicant after the application is submitted and 90 days pass with no response from the applicant, the application will be automatically rejected and a new form will have to be submitted.
- On an average an application processing time would be between 5-10 working days once the verifiers on the application respond to EC-Council’s requests for information.
- On the application, there is a section for the applicant to list a boss, supervisor, or department lead who will act as their verifier. EC-Council reaches out to the listed verifier to confirm the applicant’s experience.
- If the application is approved, the applicant will be sent instructions on purchasing the exam kit from EC-Council directly.
- If application is not approved, the application fee of USD 100 will not be refunded.
- The approved application is valid for 3 months from the date of approval so the candidate must purchase the exam kit worth $600 within 3 months. After the kit is released, the applicant has 3 months to use the codes.
- Should you require the exam code validity to be extended, kindly contact practicals@eccouncil.org before the expiry date. Only valid/ active codes can be extended.
- An application extension request will require the approval of the Director of Certification, you can send in your request to practicals@eccouncil.org
Download Brochure And Outline
Exam Sanctity
The trust that the industry places in our credentials is very important to us. We see it as our duty to ensure that the holders of this credential are proven, “hands on”, penetration testers who are able to perform in the real world to solve real world challenges.
As such, the ECSA (Practical) is designed as a hands-on exam that will test the skills of the penetration tester BEYOND just their knowledge.
This exam is an online, proctored, practical exam that can last up to 12 hours.
We know that travelling to an exam center can be difficult for many. As such, we are pleased to announce that you can take the ECSA (Practical) exam from the comfort of your home, but you need to be prepared to be proctored by a dedicated EC-Council Proctor certification team under strict supervision.