- The Number: 70% of 100 Questions
- What Is and Isn't Published About Scoring
- The Practical Math Behind 70%
- Exam Format and Delivery
- Mapping the Twelve Preparation Areas to Your Score
- Reading the Outline Carefully: Version and NIST Model
- Fees, Bundles, and Access
- A Domain-Sequenced Plan for Clearing the Bar
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- The Mile2 Certified Incident Handling Engineer exam requires a minimum of 70% on roughly 100 multiple-choice questions.
- Mile2's reviewed material does not state whether any questions are unscored, so plan to answer every item well.
- Testing runs online through the Mile2 Learning Management System, with approximately two hours allotted.
- The twelve course modules are unweighted preparation scope, not official weighted exam domains.
The Number: 70% of 100 Questions
Let's start with the fact everyone searches for. The Certified Incident Handling Engineer (C)IHE) exam from Mile2 is a 100-question multiple-choice assessment with a stated minimum passing grade of 70%. Candidates are given approximately two hours. That is the complete, officially published scoring picture in the material we reviewed, and it is consistent across the current course outline.
If the questions were all scored equally and all counted, 70% would translate to 70 correct answers out of 100. But there's an important caveat: the reviewed official material does not state whether the exam includes unscored items or how scored and unscored questions are split. That means we can describe the percentage threshold with confidence, but we should not promise that "exactly 70 correct answers" is the guaranteed cutoff in every sitting. The safest interpretation is to treat 70% as the floor and aim comfortably above it.
What Is and Isn't Published About Scoring
Being precise about what is verified helps you avoid misinformation, which is rampant for certifications that share acronyms with other credentials. Here is a clear breakdown for the Certified Incident Handling Engineer specifically.
| Scoring Detail | Status for C)IHE |
|---|---|
| Number of questions | 100 multiple-choice (stated) |
| Minimum passing grade | 70% (stated) |
| Time allowed | Approximately 2 hours (stated) |
| Delivery | Online via the Mile2 Learning Management System |
| Scored vs. unscored questions | Not stated in reviewed material |
| Official per-domain weights | Not published; none can be cited |
| Candidate pass rate | Not publicly disclosed in reviewed official material |
| Adaptive testing, open-book, calculator rules | Not verified |
| Remote proctoring rules | Not verified |
Notice what is absent: there is no published scaled-score range, no per-domain percentage breakdown, and no disclosed pass rate. If you see a site quoting a specific C)IHE pass rate or a "largest domain" percentage, treat it skeptically. For the data that does exist, see our discussion in C)IHE Pass Rate 2026: What the Data Shows, and for a sense of how demanding the test feels, read How Hard Is the C)IHE Exam? Complete Difficulty Guide 2026.
The Practical Math Behind 70%
Even without published weights, you can reason about what 70% demands. On a 100-question exam, every miss costs you roughly one percentage point (assuming all items count). That gives you a tolerance of about 30 incorrect answers before you fall below the line. For a two-hour window, you have on average about 72 seconds per question.
- Pacing target: Work through the first pass at roughly a minute per item, flagging anything that needs a second look, and bank the leftover time for review.
- Error budget: Thirty misses sounds generous, but incident handling questions are often scenario-based with plausible distractors. Clustered weakness in one area can burn through that budget quickly.
- Guessing strategy: Nothing in the reviewed material indicates a penalty for wrong answers, but because that rule isn't verified, confirm the instructions presented at the start of your sitting before deciding how aggressively to guess.
Exam Format and Delivery
The C)IHE exam is delivered online through the Mile2 Learning Management System. It is a multiple-choice exam only; the reviewed material does not establish any practical, lab-based component for the certification itself. This is worth stating plainly because the associated training can include Cyber Range exercises. Those exercises support learning, but they do not prove or imply a hands-on certification exam. Your score is determined by the multiple-choice questions.
Several administrative rules remain unverified in the reviewed sources: whether the exam is open-book, whether a calculator is permitted, how remote proctoring is handled, and whether the test is adaptive. Do not assume any of these. Before exam day, read the instructions inside your Mile2 account, and review the broader C)IHE Requirements 2026: Eligibility, Prerequisites & How to Qualify article for the suggested background: about 12 months of network-technology experience, networking and TCP/IP knowledge, and essential Linux knowledge. Taking the course is not required to buy the exam.
Mapping the Twelve Preparation Areas to Your Score
The twelve substantive modules of the current Mile2 course outline (excluding the Module 00 introduction) are the best available map of what the exam draws on. Critically, these are unweighted preparation headings, not an official, exhaustive exam blueprint. Mile2 has not supplied percentages, so no domain can be labeled as the largest. Any allocation of your study time is therefore editorial judgment, not an official ratio.
For a deeper tour of each area, see C)IHE Exam Domains 2026: Complete Guide to All 12 Content Areas. Here is how the areas cluster in a way that is useful for scoring.
Foundations and Governance (Domains 1-5)
These areas cover what an incident is, how incident handling differs from incident response, and how organizations formalize the capability.
- Incident Handling Explained: definitions of an incident, the distinction between incident handling and incident response, the response process, and the case for a response plan.
- Incident Response Policy, Plan and Procedure Creation: the difference between policy, plan, and procedures, plus sharing information with outside parties.
- Incident Response Team Structure: team models, how to select one, personnel, and organizational dependencies.
- Incident Response Team Services: intrusion detection, advisory distribution, education and awareness, and information sharing.
- Incident Response Recommendations: establishing a formal capability, information sharing, and building a team.
The Operational Lifecycle (Domains 6-9)
These areas follow an incident from readiness through aftermath, and they are where scenario questions tend to feel most practical.
- Preparation: threat hunting, threat analysis frameworks, tools and toolkits, policy, procedures, and preventing incidents. (The issuer prints this as Chapter 06 within the same sequential list.)
- Detection and Analysis: attack vectors, signs of an incident, sources of precursors and indicators, analysis, documentation, prioritization, and notification.
- Containment, Eradication and Recovery: choosing a containment strategy, gathering and handling evidence, identifying attacking hosts, and eradication and recovery.
- Post Incident Activity: lessons learned, using collected incident data, and evidence retention.
Process Maturity and Collaboration (Domains 10-12)
The closing areas reward candidates who think beyond a single incident.
- Incident Handling Checklist: why and how to build checklists.
- Incident Handling Recommendations: the recommendations themselves and implementing threat intelligence.
- Coordination and Information Sharing: coordination, purple teaming, information sharing techniques, granular information sharing, and sharing recommendations.
Because there are no official weights, a sensible way to protect your 70% is to avoid leaving any single area thin. A candidate who is excellent at detection but vague on team models and information-sharing concepts is gambling with an unknown distribution. The study approach in C)IHE Study Guide 2026: How to Pass on Your First Attempt builds on this balanced philosophy.
Reading the Outline Carefully: Version and NIST Model
One detail that trips up careful candidates is the age of the source material. The currently linked course outline carries a version string of vs.922021 and describes an older four-phase incident response model aligned to NIST 800-61. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted that revision for the C)IHE exam was not verified.
Key Takeaway
Study the four-phase model as it appears in the Mile2 outline, since that is the documented course content, but do not claim it proves anything about Revision 3. If your exam prep touches NIST guidance, learn the outline's framing first, then treat any Revision 3 differences as supplementary context rather than assumed exam content.
This distinction matters for passing: questions will follow what Mile2 teaches. Anchoring to the published outline is a safer bet than importing newer framework terminology and answering the way a different document would. The four-phase flow maps naturally onto Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post Incident Activity.
Fees, Bundles, and Access
Money questions often follow passing-score questions, so here is what is verified. The official indexed Exam Combo, which includes the exam, a simulator, and a guide, was listed at USD $500 on sale against an original price of $795. The bare-exam fee, any member versus nonmember distinction, checkout taxes, and the duration of the sale were not verified, so confirm current pricing on Mile2's site before budgeting. You can buy the exam without purchasing the course.
For a fuller treatment of costs and what to weigh, see C)IHE Certification Cost 2026: Complete Pricing Breakdown. The bundled simulator is relevant to your score: it is the closest official way to gauge how you handle the question style before committing to a sitting.
A Domain-Sequenced Plan for Clearing the Bar
Rather than a generic schedule, sequence your preparation so that early weeks build the vocabulary that later scenario questions assume. This is editorial guidance, not an official weighting.
Vocabulary and Governance
- Domains 1-2: incident vs. incident handling vs. incident response; policy vs. plan vs. procedures.
- Learn why the distinctions matter, since definition-style questions are easy points to bank.
Teams and Services
- Domains 3-5: team models and selection criteria, personnel, dependencies, and services such as advisory distribution.
- Practice matching an organization's size and structure to an appropriate team model.
Preparation and Detection
- Domains 6-7: threat hunting, analysis frameworks, indicators vs. precursors, prioritization, and notification.
- Run scenario drills on classifying signs of an incident.
Response, Aftermath, and Collaboration
- Domains 8-12: containment strategy trade-offs, evidence handling, lessons learned, checklists, threat intel, purple teaming, and granular sharing.
- Finish with full-length timed practice, targeting well above 70%.
For quick end-of-prep review, the condensed facts in C)IHE Cheat Sheet 2026: One-Page Review of Must-Know Facts pair well with timed question sets. When you are ready to test yourself under realistic conditions, our C)IHE practice tests let you rehearse the pacing and question style that determine whether you land above the line.
After You Pass: Validity and Renewal
Clearing 70% is the start of a three-year validity window. Under the dedicated renewal policy, maintaining the credential involves earning 60 qualifying CEUs, agreeing to Mile2's policies and ethics, and paying the applicable renewal fee (the amount was not verified). Older course PDFs mention a current-exam retake and 20 CEUs per year; those are outdated recertification wording, so rely on the current renewal policy rather than combining both requirements. Also remember that CEUs are a maintenance concept, not exam weights.
If you are weighing whether the credential pays off, explore Is the C)IHE Certification Worth It? Complete ROI Analysis 2026 and the hiring landscape in C)IHE Jobs. Roles that touch SOC operations, incident response coordination, and security program governance are where this knowledge applies most directly. To confirm the background you should bring, revisit the foundations in What Is C)IHE Certification? and, if you are still deciding on a path, the course-focused C)IHE Training overview. You can start sharpening your readiness today on our main practice site.
Frequently Asked Questions
The Mile2 Certified Incident Handling Engineer exam has a stated minimum passing grade of 70%. The exam consists of 100 multiple-choice questions with approximately two hours allotted. Mile2's reviewed material does not publish a scaled-score range.
Not necessarily as a guarantee. The 70% threshold is stated, but the reviewed material does not say how many questions are scored versus unscored. Aim well above 70% in practice so the unknown split cannot hurt you.
No official weighting has been published, so no domain can be named the largest. The twelve areas, from Incident Handling Explained through Coordination and Information Sharing, are unweighted preparation scope drawn from the Mile2 course outline.
The reviewed material describes a 100-question multiple-choice exam. Cyber Range exercises are part of training, but they do not establish a practical certification exam component.
Under the dedicated renewal policy, certification is valid for three years. Renewal involves 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee, whose amount was not verified.
Yes. Course purchase is not required to buy the exam. Mile2 suggests about 12 months of network-technology experience, networking and TCP/IP knowledge, and essential Linux knowledge, but no mandatory degree or reference count was verified.