- How to Read the Twelve Content Areas
- Exam Format and Registration Mechanics
- Areas 1-5: Foundations, Policy, and Team Design
- Areas 6-9: The Operational Core
- Areas 10-12: Checklists, Recommendations, and Coordination
- The NIST 800-61 Model Question
- Sequencing the Twelve Areas in Your Prep
- Who Values This Credential
- Renewal and Maintenance
- Frequently Asked Questions
- The twelve areas mirror Modules 01-12 of Mile2's course outline; they are unweighted preparation scope, not official exam percentages.
- The exam is 100 multiple-choice questions, roughly two hours, with a 70% minimum to pass.
- Testing runs online through the Mile2 Learning Management System; buying the course is not required to buy the exam.
- The current outline describes the older four-phase NIST 800-61 model, so learn that model's vocabulary precisely.
How to Read the Twelve Content Areas
The Certified Incident Handling Engineer (C)IHE) credential from Mile2 is built around a course outline that runs from Module 01 through Module 12, plus a Module 00 course introduction. The twelve substantive modules are the practical scope for exam preparation, and this guide treats them as twelve content areas. One caution up front: Mile2's currently linked outline does not publish percentage weights for these areas. Anyone who tells you that a particular domain makes up a specific share of the exam is supplying a number that is not in the reviewed official material.
That framing matters for how you study. Because no weights are published, the safest strategy is balanced coverage with extra repetition on the sections where a multiple-choice question can hide a subtle distinction, such as the difference between incident handling and incident response, or between a team model and the personnel who staff it.
Exam Format and Registration Mechanics
Before diving into content, anchor yourself in the verified format. The C)IHE exam consists of 100 multiple-choice questions with an approximate two-hour time limit and a minimum passing score of 70%. The split between scored and unscored questions is not stated in the reviewed material, so do not assume every item counts. Testing is delivered online through the Mile2 Learning Management System.
| Item | What the reviewed material shows |
|---|---|
| Question count | 100 multiple-choice questions |
| Time | Approximately 2 hours |
| Passing score | 70% minimum |
| Delivery | Online via the Mile2 Learning Management System |
| Exam Combo listing | USD $500 sale / $795 original; includes exam, simulator, and guide |
| Bare-exam fee, taxes, sale duration | Not verified |
| Suggested background | 12 months network-technology experience, networking/TCP-IP knowledge, essential Linux knowledge |
| Open-book, calculator, remote-proctoring, adaptive rules | Not verified |
Two points deserve emphasis. First, the Exam Combo price is the only fee verified in the reviewed sources, and checkout taxes and the length of the sale are unconfirmed, so check the live checkout before you budget. For more on the money side, see C)IHE Certification Cost 2026: Complete Pricing Breakdown. Second, the five-day class length and the 40 CEUs attached to the course are course values. They describe the training, not the exam duration, and they are not scoring weights. For the pass-mark details, C)IHE Passing Score 2026: Exactly What You Need to Pass goes deeper, and C)IHE Requirements 2026: Eligibility, Prerequisites & How to Qualify covers the suggested background.
Areas 1-5: Foundations, Policy, and Team Design
The first five areas establish the vocabulary and organizational scaffolding of incident handling. They are less technical than the later modules, which makes them deceptively easy to skim. Resist that, because multiple-choice questions love definitional distinctions.
Domain 1: Incident Handling Explained
This opening module defines the discipline and the reasons organizations invest in it. The published sections cover what an incident is, what incident handling is, how incident handling (IH) differs from incident response (IR), the incident response process, seven reasons to assemble an incident response plan, and how to build an effective response team.
- Be able to separate "incident" from a routine event, and "IH" from "IR."
- Know the seven reasons for having a plan, as the outline specifically enumerates them.
- Understand considerations for creating a team and tips for team members.
Domain 2: Incident Response Policy, Plan and Procedure Creation
This area distinguishes three artifacts that candidates routinely blur together: the policy, the plan, and the procedures. It also covers sharing information with outside parties.
- Know what each document is for and who owns it.
- Expect scenario questions asking which artifact addresses a given gap.
- Understand the risks and rules around disclosing incident details externally.
Domain 3: Incident Response Team Structure
Here the focus is organizational: team models, how to select a model, the personnel an incident response function needs, and the dependencies an incident team has within the wider organization.
- Compare team models and the conditions that favor each.
- Recognize that selection depends on organizational context, not a single best answer.
- Know which internal groups the team depends on during an incident.
Domain 4: Incident Response Team Services
This module lists what a response team actually offers: intrusion detection, advisory distribution, education and awareness, and information sharing. Candidates should be able to match a described activity to the correct service category.
Domain 5: Incident Response Recommendations
The recommendations module consolidates guidance on establishing a formal incident response capability, establishing information sharing capabilities, and building a response team. It overlaps with earlier areas, so treat it as a synthesis check on Domains 1-4.
If these five areas feel like common sense, that is a trap. The exam tests precise terminology, and the structure of the course makes overlaps between Domains 1, 3, and 5 likely sources of look-alike answer choices. A structured approach to this early material is outlined in the C)IHE Study Guide 2026: How to Pass on Your First Attempt.
Areas 6-9: The Operational Core
The middle of the outline walks through the incident lifecycle. If you work in a security operations center, this is where your day-to-day experience helps most, though you still need to learn the course's specific framing.
Domain 6: Preparation
One quirk worth knowing: Mile2's published outline labels this item "Chapter 06" rather than "Module 06," though it sits in the same sequential list as the other modules. Treat it as the sixth content area. Its sections are introduction, threat hunting, threat analysis frameworks, tools and toolkits, policy, procedures, and preventing incidents.
Preparation: what to master
- Threat hunting as a proactive practice, distinct from reactive detection.
- Threat analysis frameworks and how they structure adversary behavior.
- The tools and toolkits a team keeps ready before an incident occurs.
- How policy and procedures support readiness, and which preventive measures reduce incident likelihood.
Domain 7: Detection and Analysis
This is the most section-dense module in the outline, with seven sections: attack vectors, signs of an incident, sources of precursors and indicators, incident analysis, incident documentation, incident prioritization, and incident notification. A reasonable editorial guess is that it rewards extra practice time, but that is advice, not a published weight.
Detection and Analysis: what to master
- Distinguish a precursor (a sign an attack may occur) from an indicator (a sign one may have occurred).
- Know common attack vectors and which signs point to which vector.
- Understand why documentation and prioritization are formal steps, not afterthoughts.
- Recognize who must be notified and when.
Domain 8: Containment, Eradication and Recovery
The sections here are selecting the right containment strategy, gathering and handling evidence, identifying the attacking hosts, and eradication and recovery. Expect scenario questions that force a tradeoff, such as preserving evidence versus stopping spread quickly.
Domain 9: Post Incident Activity
Post-incident work covers lessons learned, using collected incident data, and evidence retention. Candidates should understand how a review feeds improvements back into policy and preparation, closing the loop with Domain 6.
Areas 10-12: Checklists, Recommendations, and Coordination
The final three modules shift from running a single incident to maturing the program. They are shorter, but they hold distinctive vocabulary that appears nowhere else in the outline.
Domain 10: Incident Handling Checklist
Sections cover an introduction and building checklists. Know why checklists improve consistency under pressure and what a well-built one contains.
Domain 11: Incident Handling Recommendations
This module covers an introduction, recommendations, and implementing threat intelligence. The threat intelligence section is the one to prioritize; understand how intelligence is operationalized rather than merely collected.
Domain 12: Coordination and Information Sharing
The sections are introduction, coordination, purple teaming, information sharing techniques, granular information sharing, and sharing recommendations.
- Purple teaming blends offensive and defensive perspectives; know its purpose.
- Distinguish general information sharing from granular, field-level sharing.
- Connect this module to the external-party sharing introduced in Domain 2.
The NIST 800-61 Model Question
Here is a subtle point that trips up well-read candidates. Mile2's currently linked outline carries a version string of vs. 922021 and describes the older four-phase NIST 800-61 incident response model. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted it was not verified in the reviewed material. So treat the four-phase model as historical course content tied to the outline you are studying, not as proof that the exam follows the newest NIST revision.
Key Takeaway
Study the lifecycle as the course frames it: preparation, detection and analysis, containment/eradication/recovery, and post-incident activity. Read newer NIST material for context if you like, but do not let it override the vocabulary in the Mile2 outline when answering exam-style questions.
Sequencing the Twelve Areas in Your Prep
Because the areas are unweighted, an editorial sequence keeps your preparation balanced. The following plan front-loads definitions and ties the lifecycle modules together. It is advice, not an official schedule, and the exam itself has no practical component to rehearse; Cyber Range exercises are training and do not establish a hands-on exam.
Domains 1-2
- Lock down IH versus IR and the policy/plan/procedure distinction.
- Memorize the seven reasons for a response plan.
Domains 3-5
- Compare team models, personnel, and services.
- Use Domain 5 as a synthesis check.
Domains 6-7
- Work threat hunting, frameworks, precursors, and indicators.
- Spend extra time on the seven Detection and Analysis sections.
Domains 8-9
- Rehearse containment tradeoffs and evidence handling.
- Connect lessons learned back to Preparation.
Domains 10-12 and review
- Cover checklists, threat intelligence, purple teaming, and granular sharing.
- Finish with timed mixed-domain practice.
When you reach the timed-practice stage, use the C)IHE practice tests to simulate the 100-question, roughly two-hour pacing. The C)IHE Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful last-pass reference, and for a realistic sense of effort, read How Hard Is the C)IHE Exam? Complete Difficulty Guide 2026.
Who Values This Credential
The twelve areas map closely to roles that build and run response capability: SOC analysts moving toward incident responder titles, security engineers who draft policy and playbooks, team leads designing response structures, and coordinators who liaise with outside parties. The emphasis on policy, team models, checklists, and information sharing suggests relevance to organizations formalizing a response function rather than only to hands-on forensics specialists. No salary figure is verified in the reviewed material, so for earnings context consult C)IHE Salary Guide 2026: Complete Earnings Analysis and weigh it with the Is the C)IHE Certification Worth It? Complete ROI Analysis 2026 piece. To see role-level demand, browse C)IHE Jobs.
Renewal and Maintenance
Certification is not permanent. Under Mile2's dedicated renewal policy, the credential is valid for three years, with renewal requiring 60 qualifying CEUs, agreement to the policy and ethics terms, and payment of the applicable renewal fee (the amount is unverified). Older course PDFs contain different recertification wording, referencing a current-exam retake and 20 CEUs per year. Do not combine the two; the dedicated renewal policy is the current administrative reference. And remember that CEUs are a maintenance mechanism, never an exam weight.
Frequently Asked Questions
No. The twelve areas are the substantive modules of the course outline, offered as unweighted preparation scope. No official percentages or largest-weighted domain appear in the reviewed material.
The exam has 100 multiple-choice questions, runs approximately two hours, and requires a minimum of 70%. The scored versus unscored split is not stated. See the C)IHE Pass Rate 2026: What the Data Shows article for what is and is not publicly known about outcomes.
No. Course purchase is not required to buy the exam. The Exam Combo, listed at USD $500 sale and $795 original, bundles the exam, a simulator, and a guide, but the bare-exam fee was not verified.
No. Cyber Range exercises support training, but they do not establish a practical certification exam component. The exam format is multiple choice.
Testing is online through the Mile2 Learning Management System. Specific windows and deadlines are covered in C)IHE Exam Dates 2026: Testing Windows, Deadlines & Scheduling, and remote-proctoring rules were not verified in the reviewed sources.
Master the twelve areas as an integrated lifecycle rather than twelve isolated lists, and the overlaps that look confusing at first become the connective tissue that helps you reason through scenario questions. For another look at the full domain overview, revisit the C)IHE Exam Domains 2026: Complete Guide to All 12 Content Areas whenever you need to re-anchor your plan.