ECSA · ● Active · Professional · EC-Council
Exam facts
| Field | Value |
|---|---|
| Cost | $245 USD (knowledge exam standalone); $1,000–$1,500 USD (ECSA Practical hands-on exam); regional pricing varies |
| Duration | 240 minutes (4 hours) for knowledge exam; 720 minutes (12 hours, across two 6-hour sessions) for ECSA Practical |
| Questions | 150 multiple choice (knowledge exam) |
| Passing | 70% (105 correct answers) — dynamically adjusted based on question difficulty |
| Format | Multiple choice (knowledge) / Hands-on lab-based practical (ECSA Practical alternative) |
| Delivery | Pearson VUE (online proctored and testing centers); EC-Council ATCs for practical |
| Languages | English (primary); regional variants available |
| Valid | 3 years from pass date |
| Renewal | Retake exam OR earn qualifying ECSA Practical credential OR maintain EC-Council membership with continuing education units (CEUs) |
| Prerequisites | Formal: None; Recommended: 2+ years information security OR CEH certification |
| Released | ECSA v10 current as of 2026 (supersedes earlier versions) |
| Retiring | N/A — v10 is active as of May 2026 |
Vendor source — EC-Council Certified Security Analyst (ECSA) ↗
Official exam guide — ECSA v10 Exam Syllabus & Courseware ↗
Exam objectives — ECSA v10 Knowledge Domains ↗
About
The Certified Security Analyst (ECSA) v10 is EC-Council's professional-level penetration testing and security assessment credential, designed as the natural progression from the Certified Ethical Hacker (CEH). Launched as a follow-on to CEH, ECSA deepens expertise in penetration testing methodologies, vulnerability assessment, and security analysis with emphasis on real-world engagement practices. Unlike CEH's broad 14-domain coverage, ECSA narrows focus to deep penetration testing skills: scope definition and legal frameworks (Rules of Engagement, Statements of Work), enterprise-scale reconnaissance and OSINT, network scanning methodology selection, advanced enumeration across multiple protocols (SMB, LDAP, SNMP, NFS), vulnerability analysis tool proficiency (Nessus, OpenVAS, Nexpose), system and web application hacking at depth, wireless network penetration testing, evasion techniques (IDS/firewall/honeypot bypasses), cloud penetration testing, and professional reporting.
The knowledge exam (150 questions, 4 hours, $245 USD) is the standard offering as of 2026. EC-Council also offers the ECSA Practical exam — a performance-based 12-hour hands-on assessment (two 6-hour sessions) that requires demonstrating vulnerability discovery, analysis, and remediation recommendations in a live lab environment. The practical is optional but increasingly preferred by employers and considered the "gold standard" validation of penetration testing capability.
ECSA is positioned between CEH (entry-level, broad) and advanced certifications like OSCP (hands-on-only, 24-hour exam) or CRTP (Active Directory focused). Industry adoption remains strong in Asia-Pacific and among government contractors; North America and Western Europe often view ECSA as "professional-level but still knowledge-based," making the Practical variant more competitive.
Domain context — Security & Cybersecurity
Professional penetration testing, vulnerability assessment, and security analysis. ECSA is part of EC-Council's offensive security ecosystem, positioned for hands-on security practitioners at mid-to-senior level.
Read full deep dive — Security & Cybersecurity Domain →
Topics covered
ECSA v10 exam blueprint focuses on applied penetration testing and vulnerability assessment:
- Penetration Testing Methodologies & Planning — Engagement phases, project planning, structured approach to pen testing
- Scope Definition & Legal Agreements — Rules of Engagement (RoE), Statements of Work (SOW), scope boundaries, client communication, legal compliance
- Reconnaissance & OSINT at Scale — Passive information gathering, OSINT tools and techniques, social media intelligence, domain/network mapping
- Network Scanning & Methodology — Port scanning (Nmap, Masscan), service discovery, network topology mapping, tool selection and optimization
- Enumeration Techniques — SMB enumeration (shares, users, groups), LDAP enumeration, SNMP enumeration, NFS enumeration, DNS enumeration
- Vulnerability Analysis — Nessus, OpenVAS, Nexpose proficiency, vulnerability classification, severity assessment, remediation mapping
- System Hacking Methodology — Privilege escalation, lateral movement, credential harvesting, post-exploitation persistence
- Web Application Testing (Advanced) — Beyond OWASP Top 10: advanced SQL injection, authentication/session bypass, business logic flaws, API exploitation
- SQL Injection (In-Depth) — Boolean-based, time-based, union-based, second-order injection, WAF evasion
- Session Hijacking & Cookie Analysis — Session fixation, cookie theft, session token prediction, man-in-the-middle techniques
- Wireless Network Penetration Testing — WPA/WPA2 cracking, rogue access points, wireless reconnaissance (Aircrack-ng, Hashcat)
- Social Engineering in Pen Test Context — Phishing campaigns (authorized), pretexting, physical security testing, user awareness vulnerabilities
- Evasion Techniques — IDS/IPS evasion, firewall evasion, honeypot detection and avoidance, AV evasion
- Cloud Penetration Testing Fundamentals — AWS misconfiguration (S3, IAM, RDS), Azure RBAC issues, GCP service account abuse, cloud-native attack patterns
- Reporting & Deliverables — Executive summary writing, technical report structure, vulnerability severity scoring, remediation roadmap creation, stakeholder communication
Source: EDUSUM ECSA v10 Exam Syllabus ↗
Common skills at Security & Cybersecurity · Professional
Shared competencies for professional penetration testing and vulnerability assessment — not specific to ECSA.
- Structured penetration testing engagement planning and scope management
- Advanced network reconnaissance and OSINT tool proficiency (Shodan, Maltego, Recon-ng, Nmap scripting)
- Vulnerability assessment tool expertise (Nessus, OpenVAS, Nexpose, Qualys)
- System and application exploitation with hands-on tool chains (Metasploit, custom payloads)
- Post-exploitation and lateral movement across enterprise networks
- Web application security testing at depth (SQL injection, authentication bypass, API testing)
- Wireless network assessment and attack methodology
- Privilege escalation and persistence mechanism implementation
- Report writing for technical and executive audiences
- Rules of Engagement (RoE) and Statements of Work (SOW) understanding and compliance
- Client communication and risk translation for business stakeholders
- IDS/firewall evasion and detection avoidance techniques
- Cloud platform penetration testing (AWS, Azure, GCP basics)
Recommended courses at Security & Cybersecurity · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| EC-Council (Official) | ECSA v10 Certification Training Course | $2,500–$3,500 USD | ↗ |
| EC-Council (Official) | iLabs Advanced Penetration Testing Labs | $600–$1,500 USD (subscription) | ↗ |
| Cybrary | EC-Council Certified Security Analyst (ECSA) v10 | Free (basic) / $399/yr (premium) | ↗ |
| Udemy | Advanced Penetration Testing & ECSA Prep | $15–$80 USD | ↗ |
| INE (formerly eLearnSecurity) | Advanced Penetration Testing & ECSA Practical Prep | $499–$999 USD | ↗ |
| eLearnSecurity / INE | Practical Penetration Tester (ePPT) — ECSA equivalent | $499–$799 USD | ↗ |
| TryHackMe | Penetration Testing + Advanced Security Paths | Free / $300/yr (premium) | ↗ |
| HackTheBox | Penetration Tester & Web Security Learning Paths | Free / $250/yr (premium labs) | ↗ |
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| EDUSUM | EC-Council ECSA v10 Practice Exam | $99–$199 USD | ↗ |
| Whizlabs | ECSA v10 Practice Exam | $39–$99 USD | ↗ |
| Boson | EC-Council ECSA v10 Practice Exam | $129–$199 USD | ↗ |
| EC-Council (Official) | iLabs Hands-On Labs + Practice Questions | $600–$1,500 USD (subscription) | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| EC-Council Certified Security Analyst (ECSA) v10 Official Courseware | EC-Council | EC-Council Press | 2024 | N/A | ↗ |
| CEH Certified Ethical Hacker All-in-One Exam Guide, Fifth Edition | Matt Walker | McGraw-Hill | 2023 | 978-1264269945 | ↗ |
| The Hacker Playbook 3: Tricks, Tools, and Techniques for Penetration Testing | Peter Kim | CreateSpace Independent Publishing | 2018 | 978-1980901770 | ↗ |
| Penetration Testing: A Hands-On Introduction to Hacking | Georgia Weidman | No Starch Press | 2014 | 978-1593275846 | ↗ |
| The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws (2nd Edition) | Stuttard & Pinto | Wiley | 2011 | 978-1118026472 | ↗ |
| Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning | Gordon Lyon | Insecure.com | 2009 | 978-0979958717 | ↗ |
Typical job titles at Security & Cybersecurity · Professional
Penetration Tester · Security Analyst (Senior) · Red Team Analyst · Vulnerability Analyst · Security Consultant · Application Security Tester · Offensive Security Engineer · Pen Test Team Lead
(Job titles drawn from current job-board postings that list ECSA as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $105K–$155K (penetration tester / security analyst with ECSA or equivalent) | Glassdoor ↗ · Robert Half ↗ · Levels.fyi ↗ |
| ZAR | R425K–R770K (penetration tester, South Africa — approximately USD 105K–155K × 18 ZAR/USD) | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £62K–£92K (penetration tester / security analyst, UK market) | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €72K–€105K (penetration tester / security analyst, Germany/Netherlands/France) | Indeed DE ↗ · LinkedIn Salary Explorer ↗ |
| AUD | A$135K–A$190K (penetration tester / security analyst, Australia) | Seek ↗ · PayScale AU ↗ |
Salary note: ECSA holders typically occupy mid-to-senior offensive security roles with significantly higher earning potential than CEH-only professionals. Practical exam holders command premium salaries (15–25% premium over knowledge-only). Progression to OSCP, CRTP, or GIAC GPEN credentials elevates earning by additional 20–40%.
Skills validated
ECSA-specific — technologies, tools, and methodologies this exam actually tests.
- Nmap (advanced scripting, network topology mapping, service enumeration optimization)
- Metasploit Framework (exploitation, payload customization, post-exploitation modules)
- Burp Suite (advanced web application testing, API exploitation, WAF bypass)
- Wireshark (deep packet analysis, protocol-level vulnerability identification)
- Nessus / OpenVAS / Nexpose (vulnerability assessment workflow, remediation mapping)
- hashcat / John the Ripper (advanced password cracking, hash analysis)
- Aircrack-ng (WPA/WPA2 cracking, wireless reconnaissance)
- Maltego (OSINT data aggregation and visualization)
- SQLMap (SQL injection automation and WAF evasion)
- Kali Linux (offensive security tool suite at professional depth)
- OWASP Top 10 + advanced web vulnerability testing (SQL injection, authentication bypass, business logic flaws)
- Windows / Linux privilege escalation and lateral movement
- AWS / Azure / GCP reconnaissance and misconfiguration exploitation (S3, IAM, RBAC)
- IDS/IPS evasion and firewall bypass techniques
- Rules of Engagement (RoE) and Statements of Work (SOW) frameworks
- Professional report writing for technical and executive audiences
- Post-exploitation persistence and evidence preservation
Related certifications
- Prerequisite: EC-Council Certified Ethical Hacker (CEH) v13 ↗ — Recommended foundational cert before ECSA
- Stacks with: CompTIA Security+ (SY0-701) ↗ · CompTIA PenTest+ (PT0-003) ↗
- Hands-on alternative: EC-Council ECSA Practical Exam ↗ — Performance-based assessment of same competencies
- Next step (advanced): Offensive Security OSCP (PEN-200) ↗ · GIAC GPEN (GIAC Penetration Tester) ↗ · Certified Red Team Professional (CRTP) ↗
- Equivalent at this level: CompTIA PenTest+ (PT0-003) ↗ — CompTIA's professional-level penetration testing cert
- Adjacent at professional level: GIAC GWAPT (GIAC Web Application Penetration Tester) ↗ — Deeper web app focus
- Industry positioning note: ECSA (especially Practical) is heavily recognized in Asia-Pacific, India, and Middle East. In North America/Western Europe, OSCP and CRTP command higher market premium, though ECSA + Practical is increasingly valued as bridging cert before advanced credentials.
- Vendor overview: EC-Council Vendor Overview ↗
Sources
- EC-Council ECSA v10 Certification Page: https://eccouncil.org/train-certify/certified-security-analyst-ecsa/
- EDUSUM ECSA v10 Exam Syllabus: https://www.edusum.com/ec-council/ec-council-security-analyst-ecsa-exam-syllabus
- EC-Council iLabs Advanced Penetration Testing Labs: https://eccouncil.org/ilabs/
- Cybrary ECSA v10 Course: https://www.cybrary.it/course/certified-security-analyst-ecsa/
- EDUSUM ECSA v10 Sample Questions: https://www.edusum.com/ec-council/ec-council-ecsa-certification-sample-questions
- Whizlabs ECSA v10 Practice Exam: https://www.whizlabs.com/ecsa-v10/
- MicroTek Learning ECSA v10 Training: https://www.microteklearning.com/ec-council-certified-security-analyst-ecsa-training/
- CertWizard ECSA Exam Guide: https://certwizard.com/ec-council/ecsa
- BJSL Training Ltd ECSA v10: https://bjsl.uk/product/ec-council-security-analyst-v10-ecsa/
- Matt Walker, CEH Certified Ethical Hacker All-in-One Exam Guide (Fifth Edition), McGraw-Hill, 2023
- Peter Kim, The Hacker Playbook 3, CreateSpace, 2018
- Georgia Weidman, Penetration Testing: A Hands-On Introduction to Hacking, No Starch Press, 2014
- Glassdoor Penetration Tester Salary Data: https://www.glassdoor.com/Salaries/penetration-tester-salary-SRCH_KO0,20.htm
- Robert Half IT Security Salary Guide (2026): https://www.roberthalf.com/us/en/salary-guide/it-security
- ZA Job Market (Pnet): https://pnet.co.za/
- UK IT Jobs Watch: https://www.itjobswatch.co.uk/
Last verified: 2026-05-02
Parent ecosystem: EC-Council Pentesting & Ethical Hacking
Parent domain: Security & Cybersecurity
Vendor overview: EC-Council Vendor Overview