C)IHE logo
Focused certification exam prep
Start practice

C)IHE Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The C)IHE exam is 100 multiple-choice questions, about 2 hours, with a 70% minimum to pass.
  • The twelve modules are unweighted preparation scope, so spread study time instead of chasing a "biggest domain."
  • The linked course outline describes the four-phase NIST 800-61 model; Mile2's adoption of Revision 3 is unverified.
  • Renewal runs on a three-year cycle with 60 qualifying CEUs, a policy and ethics agreement, and a renewal fee.

Identity and Exam Format at a Glance

The Certified Incident Handling Engineer credential, abbreviated C)IHE, is issued by Mile2. This page covers that credential only. Several other certifications share a similar acronym, and mixing their details is the fastest way to study the wrong material. If you are still orienting yourself, start with What Is C)IHE Certification? or What Does C)IHE Stand For?, then return here for the condensed review.

ItemWhat the reviewed Mile2 material states
CredentialCertified Incident Handling Engineer (C)IHE)
IssuerMile2
DeliveryOnline through the Mile2 Learning Management System
Questions100 multiple-choice
DurationApproximately 2 hours
Passing gradeMinimum 70%
Scored vs. unscored splitNot stated
Candidate pass rateNot publicly disclosed in reviewed official material
Open-book, calculator, remote-proctoring, adaptive rulesNot verified
Course values are not exam values: The five-day class length and the 40 CEUs attached to the course describe the training, not the test. Do not read "five days" as exam duration or "40" as any kind of scoring weight. Likewise, Cyber Range exercises are part of the training experience and do not establish a practical, hands-on component on the certification exam.

For the exact arithmetic on what 70% means across 100 questions, see C)IHE Passing Score 2026. For realistic expectations about difficulty, read How Hard Is the C)IHE Exam?. Because the pass rate is not publicly disclosed, any figure you see quoted elsewhere should be treated as unsupported.

Registration, Fees, and Prerequisites

Pricing facts you can rely on

The official indexed Exam Combo is listed at USD $500 sale against a $795 original price, and it includes the exam, a simulator, and a guide. What is not verified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Confirm all of that at checkout before budgeting. A fuller breakdown lives in C)IHE Certification Cost 2026.

Suggested background

  • Experience: a suggested 12 months in network technology.
  • Knowledge: networking and TCP/IP fundamentals, plus essential Linux familiarity.
  • Course purchase: not required to buy the exam.
  • Degree and references: no mandatory degree or reference count was verified.

These are suggestions rather than hard gates in the reviewed material. For the full eligibility picture, see C)IHE Requirements 2026, and for scheduling logistics check C)IHE Exam Dates 2026.

The Twelve Preparation Areas, Condensed

The twelve headings below reproduce the substantive Modules 01 through 12 of the currently linked Mile2 course outline. Module 00 is a course introduction and is not counted. These are unweighted preparation headings, not an official weighted or exhaustive blueprint, and no official percentages or largest-weighted domain are supplied. Any suggested time allocation in this article is editorial. For a deeper walk through each area, use C)IHE Exam Domains 2026.

Domain 1: Incident Handling Explained

The vocabulary foundation for everything else.

  • What an incident is, and what incident handling is
  • The difference between incident handling (IH) and incident response (IR)
  • The incident response process overview
  • Seven reasons to put together an incident response plan
  • Building an effective team and the considerations for creating one
  • Tips for incident response team members

Domain 2: Incident Response Policy, Plan and Procedure Creation

Know the hierarchy and how the three documents differ.

  • Policy, plan, and procedures as separate artifacts
  • Sharing information with outside parties

Domain 3: Incident Response Team Structure

  • Team models and how to select among them
  • Incident response personnel
  • Dependencies within organizations

Domain 4: Incident Response Team Services

  • Intrusion detection
  • Advisory distribution
  • Education and awareness
  • Information sharing

Domain 5: Incident Response Recommendations

  • Establish a formal incident response capability
  • Establish information sharing capabilities
  • Building an incident response team

Domain 6: Preparation

The outline prints this one as "Chapter 06" within the same sequential list; treat it as the sixth substantive module.

  • Threat hunting and threat analysis frameworks
  • Tools and toolkits
  • Policy and procedures
  • Preventing incidents

Domain 7: Detection and Analysis

  • Attack vectors and signs of an incident
  • Sources of precursors and indicators
  • Incident analysis, documentation, prioritization, and notification

Domain 8: Containment, Eradication and Recovery

  • Selecting the right containment strategy
  • Gathering and handling evidence
  • Identifying the attacking hosts
  • Eradication and recovery

Domain 9: Post Incident Activity

  • Lessons learned
  • Using collected incident data
  • Evidence retention

Domain 10: Incident Handling Checklist

  • Building checklists

Domain 11: Incident Handling Recommendations

  • Recommendations
  • Implementing threat intelligence

Domain 12: Coordination and Information Sharing

  • Coordination and purple teaming
  • Information sharing techniques
  • Granular information sharing
  • Sharing recommendations

The Incident Lifecycle in One Pass

Domains 6 through 9 form the operational spine of the course. Reading them as a single story makes them easier to retain than twelve separate lists.

  1. Preparation: threat hunting, threat analysis frameworks, toolkits, policy, procedures, and prevention happen before anything goes wrong.
  2. Detection and analysis: recognize attack vectors, interpret precursors and indicators, analyze, document, prioritize, and notify.
  3. Containment, eradication and recovery: choose a containment strategy, handle evidence, identify attacking hosts, then eradicate and restore.
  4. Post-incident activity: lessons learned, reuse of incident data, and evidence retention.
Precursor vs. indicator: Candidates often blur these. A precursor is a sign that an incident may occur in the future; an indicator is a sign that an incident may have occurred or is occurring. Expect scenario questions that hinge on which one a given observation represents, and on what you do about it next.

The NIST Version Question

This is the single most important caveat in the reviewed material. The currently linked course outline carries the version string vs. 922021 and describes the older four-phase NIST 800-61 model. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted it was not verified.

StatementStatus
Linked outline uses the four-phase NIST 800-61 modelStated in the reviewed outline
Outline version string is vs. 922021Stated in the reviewed outline
NIST Revision 3 was published April 3, 2025True as a NIST publication date
Mile2 has adopted Revision 3 in the examNot verified

The practical takeaway: learn the four-phase model the course teaches, because that is the model its outline describes, and treat it as historical course content rather than proof of anything about Revision 3. If you want to read Revision 3 for professional growth, do so as a separate exercise and don't assume the exam reflects it.

Team Models, Services, and Personnel

Domains 3 and 4 reward candidates who can match a situation to an organizational answer. The reviewed outline lists "Team Models" and "Team Model Selection" as distinct sections, which signals that selecting a model based on organizational context is testable, not just naming models.

Key Takeaway

For Domains 3 and 4, practice answering "which approach fits this organization and why" rather than memorizing definitions. The outline pairs team models with selection criteria and organizational dependencies, so expect scenario-style reasoning about size, distribution, and who the team depends on.

For services, keep the four named in the outline straight: intrusion detection, advisory distribution, education and awareness, and information sharing. Information sharing appears again in Domains 2, 5, and 12, so it is a recurring thread worth consolidating into one mental model: what you share, with whom, how granularly, and under what policy.

Containment, Evidence, and Recovery Quick Reference

Domain 8 is where procedure meets consequence. Containment choices affect evidence, service availability, and attacker awareness, so the outline's emphasis on selecting the right strategy is a prompt to weigh trade-offs, not recite a single correct answer.

  • Containment: decide based on the incident's nature and business impact rather than defaulting to the fastest shutdown.
  • Evidence: gathering and handling are their own section; think chain of custody, documentation, and preservation before cleanup.
  • Identifying attacking hosts: understand what can and cannot be concluded from observed source addresses.
  • Eradication and recovery: remove the cause, restore systems, and validate before returning to normal operation.
  • Evidence retention (Domain 9): retention is addressed after the incident, tying back to policy.

Domain 10 (checklists) is small in the outline but easy to underuse. Know why checklists are built, what they standardize, and how they connect to the procedures from Domain 2. Domain 11 then adds recommendations and threat intelligence implementation, which links back to the threat hunting content in Domain 6.

Renewal and Validity Facts

Use the dedicated renewal policy for current administration. The attached course PDFs contain older recertification wording about retaking the current exam and earning 20 CEUs per year; do not combine that with the current policy.

Renewal elementCurrent policy
ValidityThree years
Qualifying CEUs60
AgreementPolicies and ethics
FeeApplicable renewal fee (amount unverified)
Do not stack the old and new rules: The older outline wording (a retake plus 20 CEUs per year) is superseded for current administration by the three-year, 60-CEU policy. Also keep CEUs conceptually separate from the exam: CEUs are renewal credits, not exam weights.

A Domain-Ordered Review Schedule

Since no official weights exist, this sequencing is editorial: it follows dependency order, building vocabulary first, then the lifecycle, then the organizational and coordination layers. For a fuller preparation plan, see C)IHE Study Guide 2026.

Week 1

Foundations: Domains 1 and 2

  • Lock in IH vs. IR and the policy/plan/procedure hierarchy
  • Review Linux and TCP/IP basics if rusty
Week 2

Organization: Domains 3, 4, and 5

  • Team models, selection logic, and services
  • Capability and information-sharing recommendations
Week 3

Lifecycle core: Domains 6, 7, and 8

  • Preparation through containment, eradication, and recovery
  • Precursors vs. indicators; evidence handling
Week 4

Closure and coordination: Domains 9 through 12

  • Lessons learned, checklists, threat intel, purple teaming, granular sharing
  • Timed 100-question practice runs at roughly 2 hours

Timed practice matters here because the format is 100 questions in about 2 hours. Try the full-length simulations on the main practice test site to build pacing, and use missed questions to decide which domain to revisit.

Where the Credential Fits Professionally

The skills map to security operations and incident response roles: SOC analysts, incident handlers, CSIRT members, and security engineers who participate in response. The coordination and information-sharing content also suits team leads who work across departments or with outside parties. No salary figures are verified here; for a qualitative discussion, see C)IHE Salary Guide 2026, and for a cost-benefit view, Is the C)IHE Certification Worth It?. Role listings are collected in C)IHE Jobs, and course options in C)IHE Training. When you are ready to test yourself, head to the C)IHE practice tests.

FAQ

How many questions are on the C)IHE exam and what score do I need?

The reviewed Mile2 material states 100 multiple-choice questions, approximately 2 hours, and a 70% minimum passing grade. The split between scored and unscored questions is not stated.

Are the twelve modules weighted on the exam?

No official weights were supplied. The twelve headings are unweighted course preparation scope, so no largest domain can be named. Any time allocation you plan is your own editorial choice.

Do I have to buy the course to take the exam?

No. Course purchase is not required to buy the exam. The official indexed Exam Combo at USD $500 sale ($795 original) bundles the exam, simulator, and guide, but the bare-exam fee was not verified.

Does the exam use NIST 800-61 Revision 3?

The linked course outline describes the older four-phase NIST 800-61 model and carries version string vs. 922021. NIST published Revision 3 on April 3, 2025, but Mile2's adoption of it was not verified.

How does C)IHE renewal work?

Under the dedicated renewal policy, the credential is valid for three years and renewal involves 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee. Older outline wording about a retake and 20 CEUs per year should not be applied on top of this.

Ready to pass your C)IHE exam?

Put this into practice with free C)IHE questions across every exam domain.