EC-Council Certified Security Analyst (ECSA) v10

EC-Council · ECSA · Professional

EC-Council · EC-Council Pentesting & Ethical Hacking

EC-Council Certified Security Analyst (ECSA) v10

ECSAactiveProfessional
Official EC-Council source · eccouncil.org

ECSA · ● Active · Professional · EC-Council


Exam facts

FieldValue
Cost$245 USD (knowledge exam standalone); $1,000–$1,500 USD (ECSA Practical hands-on exam); regional pricing varies
Duration240 minutes (4 hours) for knowledge exam; 720 minutes (12 hours, across two 6-hour sessions) for ECSA Practical
Questions150 multiple choice (knowledge exam)
Passing70% (105 correct answers) — dynamically adjusted based on question difficulty
FormatMultiple choice (knowledge) / Hands-on lab-based practical (ECSA Practical alternative)
DeliveryPearson VUE (online proctored and testing centers); EC-Council ATCs for practical
LanguagesEnglish (primary); regional variants available
Valid3 years from pass date
RenewalRetake exam OR earn qualifying ECSA Practical credential OR maintain EC-Council membership with continuing education units (CEUs)
PrerequisitesFormal: None; Recommended: 2+ years information security OR CEH certification
ReleasedECSA v10 current as of 2026 (supersedes earlier versions)
RetiringN/A — v10 is active as of May 2026

Vendor source — EC-Council Certified Security Analyst (ECSA) ↗

Official exam guide — ECSA v10 Exam Syllabus & Courseware ↗

Exam objectives — ECSA v10 Knowledge Domains ↗


About

The Certified Security Analyst (ECSA) v10 is EC-Council's professional-level penetration testing and security assessment credential, designed as the natural progression from the Certified Ethical Hacker (CEH). Launched as a follow-on to CEH, ECSA deepens expertise in penetration testing methodologies, vulnerability assessment, and security analysis with emphasis on real-world engagement practices. Unlike CEH's broad 14-domain coverage, ECSA narrows focus to deep penetration testing skills: scope definition and legal frameworks (Rules of Engagement, Statements of Work), enterprise-scale reconnaissance and OSINT, network scanning methodology selection, advanced enumeration across multiple protocols (SMB, LDAP, SNMP, NFS), vulnerability analysis tool proficiency (Nessus, OpenVAS, Nexpose), system and web application hacking at depth, wireless network penetration testing, evasion techniques (IDS/firewall/honeypot bypasses), cloud penetration testing, and professional reporting.

The knowledge exam (150 questions, 4 hours, $245 USD) is the standard offering as of 2026. EC-Council also offers the ECSA Practical exam — a performance-based 12-hour hands-on assessment (two 6-hour sessions) that requires demonstrating vulnerability discovery, analysis, and remediation recommendations in a live lab environment. The practical is optional but increasingly preferred by employers and considered the "gold standard" validation of penetration testing capability.

ECSA is positioned between CEH (entry-level, broad) and advanced certifications like OSCP (hands-on-only, 24-hour exam) or CRTP (Active Directory focused). Industry adoption remains strong in Asia-Pacific and among government contractors; North America and Western Europe often view ECSA as "professional-level but still knowledge-based," making the Practical variant more competitive.


Domain context — Security & Cybersecurity

Professional penetration testing, vulnerability assessment, and security analysis. ECSA is part of EC-Council's offensive security ecosystem, positioned for hands-on security practitioners at mid-to-senior level.

Read full deep dive — Security & Cybersecurity Domain →


Topics covered

ECSA v10 exam blueprint focuses on applied penetration testing and vulnerability assessment:

  • Penetration Testing Methodologies & Planning — Engagement phases, project planning, structured approach to pen testing
  • Scope Definition & Legal Agreements — Rules of Engagement (RoE), Statements of Work (SOW), scope boundaries, client communication, legal compliance
  • Reconnaissance & OSINT at Scale — Passive information gathering, OSINT tools and techniques, social media intelligence, domain/network mapping
  • Network Scanning & Methodology — Port scanning (Nmap, Masscan), service discovery, network topology mapping, tool selection and optimization
  • Enumeration Techniques — SMB enumeration (shares, users, groups), LDAP enumeration, SNMP enumeration, NFS enumeration, DNS enumeration
  • Vulnerability Analysis — Nessus, OpenVAS, Nexpose proficiency, vulnerability classification, severity assessment, remediation mapping
  • System Hacking Methodology — Privilege escalation, lateral movement, credential harvesting, post-exploitation persistence
  • Web Application Testing (Advanced) — Beyond OWASP Top 10: advanced SQL injection, authentication/session bypass, business logic flaws, API exploitation
  • SQL Injection (In-Depth) — Boolean-based, time-based, union-based, second-order injection, WAF evasion
  • Session Hijacking & Cookie Analysis — Session fixation, cookie theft, session token prediction, man-in-the-middle techniques
  • Wireless Network Penetration Testing — WPA/WPA2 cracking, rogue access points, wireless reconnaissance (Aircrack-ng, Hashcat)
  • Social Engineering in Pen Test Context — Phishing campaigns (authorized), pretexting, physical security testing, user awareness vulnerabilities
  • Evasion Techniques — IDS/IPS evasion, firewall evasion, honeypot detection and avoidance, AV evasion
  • Cloud Penetration Testing Fundamentals — AWS misconfiguration (S3, IAM, RDS), Azure RBAC issues, GCP service account abuse, cloud-native attack patterns
  • Reporting & Deliverables — Executive summary writing, technical report structure, vulnerability severity scoring, remediation roadmap creation, stakeholder communication

Source: EDUSUM ECSA v10 Exam Syllabus ↗


Common skills at Security & Cybersecurity · Professional

Shared competencies for professional penetration testing and vulnerability assessment — not specific to ECSA.

  • Structured penetration testing engagement planning and scope management
  • Advanced network reconnaissance and OSINT tool proficiency (Shodan, Maltego, Recon-ng, Nmap scripting)
  • Vulnerability assessment tool expertise (Nessus, OpenVAS, Nexpose, Qualys)
  • System and application exploitation with hands-on tool chains (Metasploit, custom payloads)
  • Post-exploitation and lateral movement across enterprise networks
  • Web application security testing at depth (SQL injection, authentication bypass, API testing)
  • Wireless network assessment and attack methodology
  • Privilege escalation and persistence mechanism implementation
  • Report writing for technical and executive audiences
  • Rules of Engagement (RoE) and Statements of Work (SOW) understanding and compliance
  • Client communication and risk translation for business stakeholders
  • IDS/firewall evasion and detection avoidance techniques
  • Cloud platform penetration testing (AWS, Azure, GCP basics)

Recommended courses at Security & Cybersecurity · Professional

ProviderTitleCostURL
EC-Council (Official)ECSA v10 Certification Training Course$2,500–$3,500 USD
EC-Council (Official)iLabs Advanced Penetration Testing Labs$600–$1,500 USD (subscription)
CybraryEC-Council Certified Security Analyst (ECSA) v10Free (basic) / $399/yr (premium)
UdemyAdvanced Penetration Testing & ECSA Prep$15–$80 USD
INE (formerly eLearnSecurity)Advanced Penetration Testing & ECSA Practical Prep$499–$999 USD
eLearnSecurity / INEPractical Penetration Tester (ePPT) — ECSA equivalent$499–$799 USD
TryHackMePenetration Testing + Advanced Security PathsFree / $300/yr (premium)
HackTheBoxPenetration Tester & Web Security Learning PathsFree / $250/yr (premium labs)

Practice exams

ProviderTitleCostURL
EDUSUMEC-Council ECSA v10 Practice Exam$99–$199 USD
WhizlabsECSA v10 Practice Exam$39–$99 USD
BosonEC-Council ECSA v10 Practice Exam$129–$199 USD
EC-Council (Official)iLabs Hands-On Labs + Practice Questions$600–$1,500 USD (subscription)

Books

TitleAuthorPublisherYearISBNURL
EC-Council Certified Security Analyst (ECSA) v10 Official CoursewareEC-CouncilEC-Council Press2024N/A
CEH Certified Ethical Hacker All-in-One Exam Guide, Fifth EditionMatt WalkerMcGraw-Hill2023978-1264269945
The Hacker Playbook 3: Tricks, Tools, and Techniques for Penetration TestingPeter KimCreateSpace Independent Publishing2018978-1980901770
Penetration Testing: A Hands-On Introduction to HackingGeorgia WeidmanNo Starch Press2014978-1593275846
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws (2nd Edition)Stuttard & PintoWiley2011978-1118026472
Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security ScanningGordon LyonInsecure.com2009978-0979958717

Typical job titles at Security & Cybersecurity · Professional

Penetration Tester · Security Analyst (Senior) · Red Team Analyst · Vulnerability Analyst · Security Consultant · Application Security Tester · Offensive Security Engineer · Pen Test Team Lead

(Job titles drawn from current job-board postings that list ECSA as required or preferred.)


Salary

RegionRangeSource
USD$105K–$155K (penetration tester / security analyst with ECSA or equivalent)Glassdoor ↗ · Robert Half ↗ · Levels.fyi ↗
ZARR425K–R770K (penetration tester, South Africa — approximately USD 105K–155K × 18 ZAR/USD)Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗
GBP£62K–£92K (penetration tester / security analyst, UK market)IT Jobs Watch ↗ · Hays ↗
EUR€72K–€105K (penetration tester / security analyst, Germany/Netherlands/France)Indeed DE ↗ · LinkedIn Salary Explorer ↗
AUDA$135K–A$190K (penetration tester / security analyst, Australia)Seek ↗ · PayScale AU ↗

Salary note: ECSA holders typically occupy mid-to-senior offensive security roles with significantly higher earning potential than CEH-only professionals. Practical exam holders command premium salaries (15–25% premium over knowledge-only). Progression to OSCP, CRTP, or GIAC GPEN credentials elevates earning by additional 20–40%.


Skills validated

ECSA-specific — technologies, tools, and methodologies this exam actually tests.

  • Nmap (advanced scripting, network topology mapping, service enumeration optimization)
  • Metasploit Framework (exploitation, payload customization, post-exploitation modules)
  • Burp Suite (advanced web application testing, API exploitation, WAF bypass)
  • Wireshark (deep packet analysis, protocol-level vulnerability identification)
  • Nessus / OpenVAS / Nexpose (vulnerability assessment workflow, remediation mapping)
  • hashcat / John the Ripper (advanced password cracking, hash analysis)
  • Aircrack-ng (WPA/WPA2 cracking, wireless reconnaissance)
  • Maltego (OSINT data aggregation and visualization)
  • SQLMap (SQL injection automation and WAF evasion)
  • Kali Linux (offensive security tool suite at professional depth)
  • OWASP Top 10 + advanced web vulnerability testing (SQL injection, authentication bypass, business logic flaws)
  • Windows / Linux privilege escalation and lateral movement
  • AWS / Azure / GCP reconnaissance and misconfiguration exploitation (S3, IAM, RBAC)
  • IDS/IPS evasion and firewall bypass techniques
  • Rules of Engagement (RoE) and Statements of Work (SOW) frameworks
  • Professional report writing for technical and executive audiences
  • Post-exploitation persistence and evidence preservation

Related certifications


Sources


Last verified: 2026-05-02

Parent ecosystem: EC-Council Pentesting & Ethical Hacking

Parent domain: Security & Cybersecurity

Vendor overview: EC-Council Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000