- Identity and Exam Format at a Glance
- Registration, Fees, and Prerequisites
- The Twelve Preparation Areas, Condensed
- The Incident Lifecycle in One Pass
- The NIST Version Question
- Team Models, Services, and Personnel
- Containment, Evidence, and Recovery Quick Reference
- Renewal and Validity Facts
- A Domain-Ordered Review Schedule
- Where the Credential Fits Professionally
- FAQ
- The C)IHE exam is 100 multiple-choice questions, about 2 hours, with a 70% minimum to pass.
- The twelve modules are unweighted preparation scope, so spread study time instead of chasing a "biggest domain."
- The linked course outline describes the four-phase NIST 800-61 model; Mile2's adoption of Revision 3 is unverified.
- Renewal runs on a three-year cycle with 60 qualifying CEUs, a policy and ethics agreement, and a renewal fee.
Identity and Exam Format at a Glance
The Certified Incident Handling Engineer credential, abbreviated C)IHE, is issued by Mile2. This page covers that credential only. Several other certifications share a similar acronym, and mixing their details is the fastest way to study the wrong material. If you are still orienting yourself, start with What Is C)IHE Certification? or What Does C)IHE Stand For?, then return here for the condensed review.
| Item | What the reviewed Mile2 material states |
|---|---|
| Credential | Certified Incident Handling Engineer (C)IHE) |
| Issuer | Mile2 |
| Delivery | Online through the Mile2 Learning Management System |
| Questions | 100 multiple-choice |
| Duration | Approximately 2 hours |
| Passing grade | Minimum 70% |
| Scored vs. unscored split | Not stated |
| Candidate pass rate | Not publicly disclosed in reviewed official material |
| Open-book, calculator, remote-proctoring, adaptive rules | Not verified |
For the exact arithmetic on what 70% means across 100 questions, see C)IHE Passing Score 2026. For realistic expectations about difficulty, read How Hard Is the C)IHE Exam?. Because the pass rate is not publicly disclosed, any figure you see quoted elsewhere should be treated as unsupported.
Registration, Fees, and Prerequisites
Pricing facts you can rely on
The official indexed Exam Combo is listed at USD $500 sale against a $795 original price, and it includes the exam, a simulator, and a guide. What is not verified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Confirm all of that at checkout before budgeting. A fuller breakdown lives in C)IHE Certification Cost 2026.
Suggested background
- Experience: a suggested 12 months in network technology.
- Knowledge: networking and TCP/IP fundamentals, plus essential Linux familiarity.
- Course purchase: not required to buy the exam.
- Degree and references: no mandatory degree or reference count was verified.
These are suggestions rather than hard gates in the reviewed material. For the full eligibility picture, see C)IHE Requirements 2026, and for scheduling logistics check C)IHE Exam Dates 2026.
The Twelve Preparation Areas, Condensed
The twelve headings below reproduce the substantive Modules 01 through 12 of the currently linked Mile2 course outline. Module 00 is a course introduction and is not counted. These are unweighted preparation headings, not an official weighted or exhaustive blueprint, and no official percentages or largest-weighted domain are supplied. Any suggested time allocation in this article is editorial. For a deeper walk through each area, use C)IHE Exam Domains 2026.
Domain 1: Incident Handling Explained
The vocabulary foundation for everything else.
- What an incident is, and what incident handling is
- The difference between incident handling (IH) and incident response (IR)
- The incident response process overview
- Seven reasons to put together an incident response plan
- Building an effective team and the considerations for creating one
- Tips for incident response team members
Domain 2: Incident Response Policy, Plan and Procedure Creation
Know the hierarchy and how the three documents differ.
- Policy, plan, and procedures as separate artifacts
- Sharing information with outside parties
Domain 3: Incident Response Team Structure
- Team models and how to select among them
- Incident response personnel
- Dependencies within organizations
Domain 4: Incident Response Team Services
- Intrusion detection
- Advisory distribution
- Education and awareness
- Information sharing
Domain 5: Incident Response Recommendations
- Establish a formal incident response capability
- Establish information sharing capabilities
- Building an incident response team
Domain 6: Preparation
The outline prints this one as "Chapter 06" within the same sequential list; treat it as the sixth substantive module.
- Threat hunting and threat analysis frameworks
- Tools and toolkits
- Policy and procedures
- Preventing incidents
Domain 7: Detection and Analysis
- Attack vectors and signs of an incident
- Sources of precursors and indicators
- Incident analysis, documentation, prioritization, and notification
Domain 8: Containment, Eradication and Recovery
- Selecting the right containment strategy
- Gathering and handling evidence
- Identifying the attacking hosts
- Eradication and recovery
Domain 9: Post Incident Activity
- Lessons learned
- Using collected incident data
- Evidence retention
Domain 10: Incident Handling Checklist
- Building checklists
Domain 11: Incident Handling Recommendations
- Recommendations
- Implementing threat intelligence
Domain 12: Coordination and Information Sharing
- Coordination and purple teaming
- Information sharing techniques
- Granular information sharing
- Sharing recommendations
The Incident Lifecycle in One Pass
Domains 6 through 9 form the operational spine of the course. Reading them as a single story makes them easier to retain than twelve separate lists.
- Preparation: threat hunting, threat analysis frameworks, toolkits, policy, procedures, and prevention happen before anything goes wrong.
- Detection and analysis: recognize attack vectors, interpret precursors and indicators, analyze, document, prioritize, and notify.
- Containment, eradication and recovery: choose a containment strategy, handle evidence, identify attacking hosts, then eradicate and restore.
- Post-incident activity: lessons learned, reuse of incident data, and evidence retention.
The NIST Version Question
This is the single most important caveat in the reviewed material. The currently linked course outline carries the version string vs. 922021 and describes the older four-phase NIST 800-61 model. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted it was not verified.
| Statement | Status |
|---|---|
| Linked outline uses the four-phase NIST 800-61 model | Stated in the reviewed outline |
| Outline version string is vs. 922021 | Stated in the reviewed outline |
| NIST Revision 3 was published April 3, 2025 | True as a NIST publication date |
| Mile2 has adopted Revision 3 in the exam | Not verified |
The practical takeaway: learn the four-phase model the course teaches, because that is the model its outline describes, and treat it as historical course content rather than proof of anything about Revision 3. If you want to read Revision 3 for professional growth, do so as a separate exercise and don't assume the exam reflects it.
Team Models, Services, and Personnel
Domains 3 and 4 reward candidates who can match a situation to an organizational answer. The reviewed outline lists "Team Models" and "Team Model Selection" as distinct sections, which signals that selecting a model based on organizational context is testable, not just naming models.
Key Takeaway
For Domains 3 and 4, practice answering "which approach fits this organization and why" rather than memorizing definitions. The outline pairs team models with selection criteria and organizational dependencies, so expect scenario-style reasoning about size, distribution, and who the team depends on.
For services, keep the four named in the outline straight: intrusion detection, advisory distribution, education and awareness, and information sharing. Information sharing appears again in Domains 2, 5, and 12, so it is a recurring thread worth consolidating into one mental model: what you share, with whom, how granularly, and under what policy.
Containment, Evidence, and Recovery Quick Reference
Domain 8 is where procedure meets consequence. Containment choices affect evidence, service availability, and attacker awareness, so the outline's emphasis on selecting the right strategy is a prompt to weigh trade-offs, not recite a single correct answer.
- Containment: decide based on the incident's nature and business impact rather than defaulting to the fastest shutdown.
- Evidence: gathering and handling are their own section; think chain of custody, documentation, and preservation before cleanup.
- Identifying attacking hosts: understand what can and cannot be concluded from observed source addresses.
- Eradication and recovery: remove the cause, restore systems, and validate before returning to normal operation.
- Evidence retention (Domain 9): retention is addressed after the incident, tying back to policy.
Domain 10 (checklists) is small in the outline but easy to underuse. Know why checklists are built, what they standardize, and how they connect to the procedures from Domain 2. Domain 11 then adds recommendations and threat intelligence implementation, which links back to the threat hunting content in Domain 6.
Renewal and Validity Facts
Use the dedicated renewal policy for current administration. The attached course PDFs contain older recertification wording about retaking the current exam and earning 20 CEUs per year; do not combine that with the current policy.
| Renewal element | Current policy |
|---|---|
| Validity | Three years |
| Qualifying CEUs | 60 |
| Agreement | Policies and ethics |
| Fee | Applicable renewal fee (amount unverified) |
A Domain-Ordered Review Schedule
Since no official weights exist, this sequencing is editorial: it follows dependency order, building vocabulary first, then the lifecycle, then the organizational and coordination layers. For a fuller preparation plan, see C)IHE Study Guide 2026.
Foundations: Domains 1 and 2
- Lock in IH vs. IR and the policy/plan/procedure hierarchy
- Review Linux and TCP/IP basics if rusty
Organization: Domains 3, 4, and 5
- Team models, selection logic, and services
- Capability and information-sharing recommendations
Lifecycle core: Domains 6, 7, and 8
- Preparation through containment, eradication, and recovery
- Precursors vs. indicators; evidence handling
Closure and coordination: Domains 9 through 12
- Lessons learned, checklists, threat intel, purple teaming, granular sharing
- Timed 100-question practice runs at roughly 2 hours
Timed practice matters here because the format is 100 questions in about 2 hours. Try the full-length simulations on the main practice test site to build pacing, and use missed questions to decide which domain to revisit.
Where the Credential Fits Professionally
The skills map to security operations and incident response roles: SOC analysts, incident handlers, CSIRT members, and security engineers who participate in response. The coordination and information-sharing content also suits team leads who work across departments or with outside parties. No salary figures are verified here; for a qualitative discussion, see C)IHE Salary Guide 2026, and for a cost-benefit view, Is the C)IHE Certification Worth It?. Role listings are collected in C)IHE Jobs, and course options in C)IHE Training. When you are ready to test yourself, head to the C)IHE practice tests.
FAQ
The reviewed Mile2 material states 100 multiple-choice questions, approximately 2 hours, and a 70% minimum passing grade. The split between scored and unscored questions is not stated.
No official weights were supplied. The twelve headings are unweighted course preparation scope, so no largest domain can be named. Any time allocation you plan is your own editorial choice.
No. Course purchase is not required to buy the exam. The official indexed Exam Combo at USD $500 sale ($795 original) bundles the exam, simulator, and guide, but the bare-exam fee was not verified.
The linked course outline describes the older four-phase NIST 800-61 model and carries version string vs. 922021. NIST published Revision 3 on April 3, 2025, but Mile2's adoption of it was not verified.
Under the dedicated renewal policy, the credential is valid for three years and renewal involves 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee. Older outline wording about a retake and 20 CEUs per year should not be applied on top of this.