EC-Council · Penetration Testing Track
Retired 2021 — now CPENT

EC-Council Certified Security Analyst

ECSA

ECSA was EC-Council's advanced penetration-testing analyst credential — the methodology-and-reporting step that sat between Certified Ethical Hacker and the Licensed Penetration Tester track. Important: EC-Council retired ECSA on March 31, 2021 and replaced it with CPENT (Certified Penetration Testing Professional), simplifying the core path to CND, CEH, and CPENT. You can no longer register for a new ECSA exam. This page explains what ECSA actually was, how its exams worked, and which credential to target today if a pen-testing certification is your goal.

4h knowledge exam
150 MCQs
70% to pass
Retired → CPENT

Pay Only After You Pass

No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider EC-Council
Status Retired 2021 → CPENT
Knowledge exam 150 MCQs · 4 hours
Passing score 70%
Practical exam 12h · 8 challenges
Delivery EC-Council ECE / iLabs
Successor CPENT
Language English
Ask About Pen-Test Help

EXAM FORMAT

How ECSA was built — at a glance (and what replaced it)

150

Knowledge exam

ECSA v10 began with a 150-question multiple-choice exam over 4 hours, requiring 70% to pass. It tested the EC-Council penetration-testing methodology end to end.

8

Practical challenges

Passing the knowledge exam unlocked the optional ECSA (Practical): a 12-hour, hands-on test of 8 real-world challenges on a live cyber range, scored on results plus your report.

2021

Retired & replaced

EC-Council retired ECSA on March 31, 2021. The advanced pen-testing slot in the core track is now filled by CPENT (Certified Penetration Testing Professional).

Two-tier structure

ECSA v10 was designed as a knowledge-plus-skills credential. The multiple-choice knowledge exam came first; candidates who passed could then attempt the separate, fully hands-on ECSA (Practical) to earn the practical designation. The two tiers were assessed independently.

Where it sits today

EC-Council collapsed the pen-testing track to three core certifications — CND, CEH, and CPENT — when ECSA was retired. If you were targeting ECSA for an advanced pen-testing credential, CPENT is the modern successor; CEH remains the foundational ethical-hacking certification a step earlier.

WHAT WAS TESTED

The four skill areas at the heart of the ECSA pen-testing methodology

1

Penetration Testing Methodology

The structured, repeatable EC-Council pen-testing process: scoping, information gathering, network and web-application testing, exploitation, and post-exploitation — applied as a documented engagement rather than ad-hoc hacking.

2

Vulnerability Assessment

Identifying, validating, and prioritising weaknesses across networks, hosts, and applications — distinguishing real exploitable findings from scanner noise and false positives.

3

Security Analysis & Exploitation

Analysing systems and chaining weaknesses into working attacks — network, web, wireless, and social-engineering vectors — to demonstrate genuine business risk against target environments.

4

Professional Report Writing

Turning findings into a clear, client-ready penetration-testing report — the differentiator ECSA emphasised most. On the Practical exam, an acceptable report was required to pass alongside solving the challenges.

ECSA's signature was treating a pen test as a documented professional engagement — methodology and reporting, not just exploitation. CPENT carries that philosophy forward into a tougher, fully practical exam, while CEH covers the foundational ethical-hacking knowledge a step earlier in the track.

DELIVERY & PROCTORING

How ECSA was delivered while it was active

Knowledge exam — proctored MCQ

The 150-question knowledge exam was delivered through the EC-Council Exam Center (and at times via Pearson VUE), as a proctored, closed-book multiple-choice test with a 4-hour limit and a 70% passing threshold.

Practical exam — live cyber range

The ECSA (Practical) ran on EC-Council's Aspen iLabs cyber range: a remotely-accessed, fully online 12-hour engagement against real networked targets. You solved at least 5 of 8 challenges and submitted a professional penetration-testing report to pass.

Eligibility

Candidates needed official EC-Council training or at least 2 years of relevant InfoSec experience — ECSA was an experienced practitioner's credential, not an entry point.

No new registrations

Since the March 2021 retirement, new ECSA exam sittings are no longer offered. Anyone seeking this skill set is routed to CPENT.

Existing holders

If you already hold ECSA, the credential remains on your record. To stay current with EC-Council's active track, CPENT is the path forward.

WHO IT WAS FOR

ECSA targeted working penetration testers — its audience now sits CPENT

  • Penetration testers ready to formalise their methodology
  • CEH holders advancing into hands-on offensive security
  • Security analysts and SOC engineers expanding into red-team work
  • Consultants who needed a recognised, report-driven pen-test cert
  • Pros chasing DoD 8570 / government-recognised credentials

PREREQUISITES & DIFFICULTY

An experienced-practitioner exam — and an honest note on status

  • Official EC-Council training or 2+ years of InfoSec experience
  • Comfort with Linux, networking, and common pen-test tooling
  • CEH-level ethical-hacking knowledge as a foundation
  • Clear technical writing for the required pen-test report

Status note: ECSA is retired, so there is no current ECSA sitting to prepare for. The knowledge exam was a methodology-heavy MCQ test; the Practical was a demanding 12-hour live engagement. If a pen-testing credential is your goal, target CPENT — or CEH if you are earlier in the track.

HOW EXAM ASSIST HELPS YOU PASS

ECSA itself is retired, so we won't pretend you can still sit it. What we do is point you at the credential you can actually earn today — CPENT for advanced penetration testing, or CEH if you're a step earlier — and pair you with a vetted EC-Council specialist on a pay-after-you-pass model. The risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.

1

Tell us your goal

Let us know you were aiming for ECSA and where you are in the EC-Council track. We'll confirm the right active credential — usually CPENT or CEH — over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and target exam and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You're matched with an EC-Council pen-test specialist who maps the work around the cyber-range format, the proctoring environment, and the reporting requirement — discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing result is confirmed. No verified result, nothing owed.

Aiming for an EC-Council pen-test cert?

Tell us your goal and we'll line you up with the right active exam — pay only after you pass.

Get Help — Pay After You Pass

FREQUENTLY ASKED

Straight answers about ECSA and its successor

Is the ECSA exam still available? +
No. EC-Council retired the ECSA (EC-Council Certified Security Analyst) program on March 31, 2021. New candidates can no longer register for ECSA. EC-Council now points anyone seeking an advanced penetration-testing credential to CPENT (Certified Penetration Testing Professional), which replaced ECSA in the core track alongside CND and CEH.
What replaced the ECSA certification? +
CPENT — the Certified Penetration Testing Professional — is the direct successor to ECSA. It is a fully hands-on credential built around a live cyber range, covering advanced exploitation, pivoting, privilege escalation, binary exploitation, and professional reporting. If you were aiming for ECSA, CPENT is the credential to target today.
What was the ECSA exam format? +
ECSA v10 had two tiers. The knowledge exam was 150 multiple-choice questions over 4 hours with a 70% passing score, delivered through the EC-Council Exam Center. Candidates who passed could attempt the separate ECSA (Practical) exam — a 12-hour, hands-on test of 8 real-world challenges on the Aspen iLabs cyber range, requiring at least 5 solved challenges plus an acceptable penetration-testing report.
Was ECSA hard? +
The knowledge exam was a methodology-heavy multiple-choice test that rewarded knowing the EC-Council pen-testing process. The ECSA (Practical) was genuinely demanding: a 12-hour live engagement against networked targets, scored on solved challenges and the quality of your written report. CPENT, its successor, is considered harder still and is fully practical.
Can Exam Assist still help with ECSA? +
ECSA is retired, so there is no current ECSA exam to register for. We orient our help toward the credential you can actually sit today — CPENT for advanced penetration testing, or CEH if you are earlier in the EC-Council track. Tell us your goal and we'll give you an honest answer on the right exam and whether we can help.
Do I pay Exam Assist before or after I get my result? +
You settle only after your verified passing result is confirmed. There is no upfront fee — you share your details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.

KEEP EXPLORING

Get help and explore active EC-Council and pen-testing exams

YOUR PEN-TEST CERT, HANDLED

ECSA is retired — so we'll point you to the credential you can actually earn today and help you pass it with no upfront fee. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US