- What You Are Actually Preparing For
- Keeping the Credential Straight
- The Twelve Preparation Areas, Explained
- The Four-Phase NIST Model and the Version Question
- Registration and Cost Mechanics
- A Study Sequence Built Around the Course Outline
- Thinking Like the Multiple-Choice Questions
- After You Pass: Renewal and Career Context
- Frequently Asked Questions
- The exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum to pass.
- Mile2's twelve substantive course modules are unweighted preparation scope, not official weighted exam domains.
- Cyber Range exercises support training; they do not establish a practical exam component.
- Renewal follows a three-year cycle with 60 qualifying CEUs, a policy and ethics agreement, and a fee.
What You Are Actually Preparing For
The Certified Incident Handling Engineer credential, abbreviated C)IHE, is issued by Mile2 and tested online through the Mile2 Learning Management System. The format is straightforward: 100 multiple-choice questions, approximately two hours, and a minimum score of 70%. The scored versus unscored question split is not stated in the reviewed official material, so do not assume every item counts.
Mile2 suggests about 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. Those are suggestions, not a verified gate. For a full breakdown of eligibility, see our guide to C)IHE requirements and prerequisites. Buying the course is also not required to purchase the exam.
Equally important is what the exam is not. The course includes Cyber Range training, but that does not establish a hands-on practical component on the certification exam. Prepare for a knowledge exam delivered as multiple-choice questions, and treat lab work as a way to make concepts stick.
Keeping the Credential Straight
The acronym is shared with other credentials in the wider industry, which creates confusion when you search for study material. Everything in this guide refers only to the Mile2 Certified Incident Handling Engineer. If you want a primer on the name itself, our pages on what C)IHE stands for and what C)IHE certification is cover the basics. Before using any third-party notes, confirm they were written for the Mile2 course; material from similarly named credentials can steer you toward the wrong content.
The Twelve Preparation Areas, Explained
The current Mile2 course outline contains twelve substantive modules after an introductory Module 00. These are unweighted course preparation headings, not an official weighted or exhaustive exam blueprint, and no official percentages are published for them. Our complete guide to all 12 content areas goes deeper on each; here is how to think about them as a candidate.
Foundations: Modules 1 through 5
Incident Handling Explained
This opening area establishes vocabulary. Expect to distinguish an event from an incident, and to separate incident handling from incident response.
- What an incident is and what incident handling is
- The difference between IH and IR
- The incident response process
- Seven reasons to build an incident response plan
- Building an effective team, with considerations and tips for members
Incident Response Policy, Plan and Procedure Creation
Learn how the three artifacts differ and how they relate. Policy sets authority and expectations, the plan describes the approach and resources, and procedures give step-level instructions.
- Policy, plan, and procedures as distinct documents
- Sharing information with outside parties
Incident Response Team Structure
Questions here tend to be scenario-driven: given an organization's size, distribution, and constraints, which team model fits?
- Team models and how to select among them
- Incident response personnel
- Dependencies within organizations
Incident Response Team Services
A team does more than react. This area covers the services a team can provide.
- Intrusion detection
- Advisory distribution
- Education and awareness
- Information sharing
Incident Response Recommendations
This area consolidates guidance on establishing a formal capability, building information sharing capabilities, and building the team.
The Lifecycle Core: Modules 6 through 9
These four areas map to the working phases of an incident, and most candidates find them the most intuitive because they follow a timeline. One quirk to note: the issuer prints "Chapter 06" for the Preparation module within the same sequential list, so do not be thrown if you see that label in the outline.
Preparation
Preparation is broader than writing a plan. The outline lists threat hunting, threat analysis frameworks, tools and toolkits, policy, procedures, and preventing incidents.
- Threat hunting versus passive monitoring
- Threat analysis frameworks and why teams adopt them
- Assembling tools and toolkits before you need them
- Preventive controls that reduce incident volume
Detection and Analysis
Expect questions that ask you to classify what you are seeing and decide what comes next.
- Attack vectors and signs of an incident
- Sources of precursors and indicators
- Incident analysis, documentation, prioritization, and notification
Containment, Eradication and Recovery
Know how to choose a containment strategy and why the choice depends on business impact, evidence needs, and the risk of the attacker noticing.
- Selecting the right containment strategy
- Gathering and handling evidence
- Identifying the attacking hosts
- Eradication and recovery
Post Incident Activity
The phase candidates tend to underestimate. Lessons learned, reuse of collected incident data, and evidence retention are fair game.
Maturity and Collaboration: Modules 10 through 12
Incident Handling Checklist
A short area focused on introducing checklists and building them.
Incident Handling Recommendations
Covers general recommendations and implementing threat intelligence.
Coordination and Information Sharing
This area includes coordination, purple teaming, information sharing techniques, granular information sharing, and sharing recommendations.
- Why coordination across parties matters during an incident
- Purple teaming as a collaboration between offense and defense
- Granular sharing: deciding how much detail goes to whom
The Four-Phase NIST Model and the Version Question
The current linked outline carries the version string vs. 922021 and describes the older four-phase NIST SP 800-61 model: preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. You can see that structure in modules 6 through 9 above.
NIST published Revision 3 of its incident response guidance on April 3, 2025. Whether Mile2 has adopted it for the exam has not been verified. The practical advice is to learn the four-phase model the way the course presents it, since that is what the outline reflects, and treat the newer revision as supplementary reading rather than a substitute. Do not rewrite your mental model around Revision 3 until Mile2 indicates otherwise.
Registration and Cost Mechanics
The official indexed Exam Combo is listed at USD $500 on sale, against an original price of $795, and includes the exam, a simulator, and a guide. What has not been verified: the bare-exam fee, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Because of that, confirm the current price at checkout rather than budgeting from a sale figure. Our C)IHE certification cost breakdown tracks the pricing picture in more detail.
Rules on open-book use, calculators, remote proctoring, and adaptive delivery are also not verified. Read the exam-day instructions inside the Mile2 Learning Management System before test day and run any required system check early. For timing questions, see our page on exam dates and scheduling.
| Item | What is known |
|---|---|
| Format | 100 multiple-choice questions |
| Duration | Approximately 2 hours |
| Passing score | Minimum 70% |
| Delivery | Online via the Mile2 Learning Management System |
| Exam Combo | $500 sale / $795 original; includes exam, simulator, and guide |
| Pass rate | Not publicly disclosed in reviewed official material |
| Practical component | Not established; Cyber Range is training only |
Two course values are easy to misread as exam facts. The five-day class and 40 CEUs belong to the training course; they are not the exam duration and not scored weights. For the scoring threshold specifically, see what you need to pass.
A Study Sequence Built Around the Course Outline
Because no official weighting is published, any time allocation is an editorial judgment, not a statement about how the exam is scored. The sequence below follows the logical order of the outline: vocabulary and organization first, then the lifecycle, then collaboration. It is a template, so stretch or compress it to match your own experience.
Vocabulary and the response process
- Incident Handling Explained: incident versus event, IH versus IR
- Policy, plan, and procedure creation as three distinct documents
Organization and services
- Team structure: models, selection, personnel, dependencies
- Team services and the recommendations modules
Preparation and detection
- Threat hunting, frameworks, toolkits, prevention
- Attack vectors, indicators, analysis, prioritization, notification
Response, aftermath, and collaboration
- Containment strategy, evidence handling, eradication, recovery
- Lessons learned and retention, checklists, threat intel, coordination and purple teaming
Reserve the final days for timed practice. If you have a background in networking and Linux, you may need less time on the technical flavor of detection and more on the policy and organizational modules, which trip up hands-on practitioners. Our difficulty guide discusses where candidates typically feel stretched, and the cheat sheet works well as a final-day review.
Thinking Like the Multiple-Choice Questions
With 100 multiple-choice items and a 70% bar, you can miss a meaningful number of questions, but not casually. A few patterns are worth rehearsing.
Sequence and phase questions
Many items will hinge on which phase an activity belongs to. Drill the mapping: is a given action preparation, detection and analysis, containment, eradication and recovery, or post-incident activity? Evidence gathering, for instance, sits in the containment module, while using collected incident data sits in post-incident work.
Document-type questions
Be ready to tell policy, plan, and procedure apart. A common failure mode is choosing the answer that describes step-by-step instructions when the question is asking about the document that grants authority.
Judgment questions
Containment strategy selection, incident prioritization, and information sharing decisions reward weighing tradeoffs. When two answers look right, favor the one that protects evidence, limits business impact, and follows the organization's documented process.
Key Takeaway
Do not memorize module titles in isolation. For each of the twelve areas, be able to explain what problem it solves, who is responsible, and what artifact or decision it produces. That framing carries over to scenario questions.
After You Pass: Renewal and Career Context
Under the current dedicated renewal policy, the certification is valid for three years. Renewal calls for 60 qualifying CEUs, agreement to the policy and ethics terms, and payment of the applicable renewal fee, whose amount was not verified. Older course PDFs contain wording about a current-exam retake and 20 CEUs per year; those are outdated, so follow the dedicated renewal policy rather than requiring both. Also, CEUs are a renewal concept and have nothing to do with exam scoring.
On the career side, incident handling skills map to roles such as security analyst, SOC team member, incident responder, and CSIRT staff. Because no verified salary data or pass-rate statistics are supplied here, we avoid quoting numbers; the salary guide, jobs overview, and ROI analysis discuss the decision qualitatively, and the pass rate page explains why no official figure can be cited.
When you are ready to test yourself under timed conditions, the practice questions on the main practice test site are a good place to measure readiness across all twelve areas before you book.
Frequently Asked Questions
The exam has 100 multiple-choice questions to be completed in approximately two hours, with a minimum passing score of 70%. The split between scored and unscored questions is not stated in the reviewed official material.
No. They are unweighted preparation headings drawn from the current Mile2 course outline. No official percentages are published, so no module can be called the largest. Treat all twelve as in scope and allocate study time based on your own gaps.
Nothing in the reviewed official material establishes a practical exam component. The course includes Cyber Range exercises for training, but those support learning rather than proving a practical certification exam.
No. Course purchase is not required to buy the exam. Mile2 suggests 12 months of network-technology experience plus networking, TCP/IP, and essential Linux knowledge, but no mandatory degree or reference count was verified.
Under the current renewal policy, three years. Renewal involves 60 qualifying CEUs, agreement to policies and ethics, and a renewal fee whose amount was not verified. Check Mile2's renewal page for the latest terms.