- What the Certified Incident Handling Engineer Credential Is
- Exam Format, Registration and Pricing Mechanics
- The Twelve Preparation Areas, Module by Module
- The NIST Version Question: What the Outline Actually Says
- Prerequisites and Who Should Sit This Exam
- Sequencing Your Preparation Around the Twelve Areas
- Renewal: Three Years, 60 CEUs and the Dedicated Policy
- Where the Credential Fits in a Career
- Frequently Asked Questions
- C)IHE is Mile2's Certified Incident Handling Engineer exam: 100 multiple-choice questions, about two hours, 70% minimum to pass.
- The twelve course modules are unweighted preparation scope, not an official weighted exam blueprint.
- The current linked outline carries version string vs.922021 and teaches the older four-phase NIST 800-61 model.
- Certification lasts three years and renewal requires 60 qualifying CEUs plus agreement to policies and ethics.
What the Certified Incident Handling Engineer Credential Is
The Certified Incident Handling Engineer credential, abbreviated C)IHE, is a Mile2 certification built around the full lifecycle of handling a security incident: building the capability, preparing, detecting, containing, recovering and learning from what happened. It is not a general security survey. Its subject matter is the organizational and procedural machinery of incident response, covering policies, team structures, services, checklists and coordination with outside parties, alongside the technical activity of analyzing and containing an incident.
If you are still orienting yourself on the terminology, our explainers on what C)IHE certification is and what C)IHE stands for cover the basics. This article goes deeper into how the exam is structured, what the preparation scope contains and how to sequence your study. If you want to test yourself as you read, the C)IHE practice tests are the fastest way to find your weak spots.
Exam Format, Registration and Pricing Mechanics
Testing is delivered online through the Mile2 Learning Management System. The published parameters are straightforward:
| Attribute | What the reviewed official material states |
|---|---|
| Question count | 100 multiple-choice questions |
| Duration | Approximately 2 hours |
| Minimum passing score | 70% |
| Delivery | Online via the Mile2 Learning Management System |
| Scored vs. unscored items | Split not stated |
| Candidate pass rate | Not publicly disclosed in the reviewed official material |
| Open-book, calculator, remote-proctoring and adaptive rules | Not verified |
That last row matters. Because the reviewed material does not confirm proctoring or open-book rules, confirm them directly inside your Mile2 account before exam day rather than assuming. For the specifics of scoring, see our breakdown of the C)IHE passing score, and for what is and is not known about outcomes, read the discussion in C)IHE pass rate.
What the exam costs
The official indexed Exam Combo, which includes the exam, a simulator and a guide, was listed at USD $500 on sale against an original price of $795. Several details remain unverified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes and how long the sale price runs. Treat the combo figure as a reference point and confirm the live price at checkout. Our C)IHE certification cost guide tracks the pricing picture in more detail.
One useful fact: purchasing the course is not required to buy the exam. Candidates who already have incident response experience can go straight to the exam, while those who prefer structured instruction can take the class. The five-day class and its 40 CEUs are course values; they describe the training, not the exam's duration or any scoring weight.
The Twelve Preparation Areas, Module by Module
The preparation scope maps to the twelve substantive modules of the currently linked Mile2 course outline. Module 00 is a course introduction and is not counted. Crucially, these are unweighted course preparation headings, not an official weighted or exhaustive examination blueprint. No official percentages are published, so no domain can honestly be called the largest. Any allocation of your study hours is editorial judgment, not an insider breakdown. For a longer treatment, see C)IHE exam domains: a complete guide to all 12 content areas.
Domain 1: Incident Handling Explained
The conceptual foundation. You must be able to define an incident, distinguish incident handling from incident response, and describe the response process end to end.
- What is an incident, and what is incident handling
- The difference between IH and IR
- Seven reasons to put together an incident response plan
- How to build an effective team, considerations for creating one, and tips for team members
Domain 2: Incident Response Policy, Plan and Procedure Creation
Expect questions that test whether you can tell the three documents apart and know what belongs in each.
- Incident response policy versus plan versus procedures
- Sharing information with outside parties
Domain 3: Incident Response Team Structure
Organizational design questions: which team model suits which organization and why.
- Team models and team model selection
- Incident response personnel
- Dependencies within organizations
Domain 4: Incident Response Team Services
What a team actually offers its constituency beyond reacting to alerts.
- Intrusion detection
- Advisory distribution
- Education and awareness
- Information sharing
Domain 5: Incident Response Recommendations
Program-level guidance: establishing a formal capability, establishing information sharing capabilities and building the team.
Domain 6: Preparation
The issuer prints this one as "Chapter 06" within the same sequential list, a small quirk worth knowing so you are not confused by the labeling. It is the most hands-on of the planning modules.
- Threat hunting and threat analysis frameworks
- Tools and toolkits
- Policy and procedures
- Preventing incidents
Domain 7: Detection and Analysis
The operational core. Know how incidents present themselves and how analysts work them.
- Attack vectors and signs of an incident
- Sources of precursors and indicators
- Incident analysis, documentation, prioritization and notification
Domain 8: Containment, Eradication and Recovery
Decision-driven material: choosing a containment strategy, handling evidence properly, identifying attacking hosts, then eradicating and recovering.
Domain 9: Post Incident Activity
Lessons learned, using collected incident data and evidence retention.
Domain 10: Incident Handling Checklist
Why checklists matter and how to build them so responders act consistently under pressure.
Domain 11: Incident Handling Recommendations
Consolidated recommendations, including implementing threat intelligence.
Domain 12: Coordination and Information Sharing
Coordination, purple teaming, information sharing techniques, granular information sharing and sharing recommendations.
The NIST Version Question: What the Outline Actually Says
This is a point where careful reading pays off. The current linked outline bears the version string vs.922021 and describes the older four-phase NIST 800-61 model. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted it into the C)IHE course or exam was not verified. The four-phase model in the outline is historical course content; it is not evidence that Mile2 has moved to Revision 3.
The practical takeaway is to study the phase structure as the outline presents it, and not to assume that newer NIST framing will appear on your exam. If you also read Revision 3 for professional development, keep it clearly separate from your exam preparation, and avoid answering a C)IHE question using vocabulary the course never taught. Our C)IHE study guide reinforces this by anchoring preparation to the published outline.
Key Takeaway
Prepare from the outline Mile2 actually publishes. Treat the four-phase NIST 800-61 content as the working model for the exam, and verify any change in the course materials you receive.
Prerequisites and Who Should Sit This Exam
Mile2 suggests about 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions rather than hard gates: no mandatory degree and no reference count was verified. Our C)IHE requirements page walks through qualification in more depth.
In practice, the ideal candidate is someone who already touches security operations: a SOC analyst moving toward a lead role, a sysadmin who gets pulled into every outage, or a security generalist being asked to write the organization's first response plan. Because the scope is as much about building a response capability as executing one, managers and team leads can benefit as well.
Is it a hard exam?
Difficulty is subjective and no pass rate is published, so honest answers depend on your background. Candidates with real response experience will find the process vocabulary familiar; those without it may find the policy-versus-plan-versus-procedure distinctions and team-model questions less intuitive than the technical ones. See how hard the C)IHE exam is for a fuller discussion.
Sequencing Your Preparation Around the Twelve Areas
Since the exam has no published domain weights, spread your effort across all twelve areas instead of betting on a guess about which dominates. A sensible order follows the incident lifecycle, because later modules build on earlier vocabulary. The allocation below is editorial, not an official weighting.
Foundations and Governance
- Domains 1 and 2: definitions, IH versus IR, policy versus plan versus procedure
- Write one-line distinctions you can recall instantly
Team and Services
- Domains 3, 4 and 5: team models, personnel, services and program recommendations
- Practice matching a scenario to the most suitable team model
Preparation, Detection and Analysis
- Domains 6 and 7: threat hunting, frameworks, toolkits, indicators and prioritization
- Spend extra time here if you lack hands-on SOC experience
Response, Recovery and Review
- Domains 8 and 9: containment strategy, evidence handling, recovery and lessons learned
- Domains 10, 11 and 12: checklists, recommendations, coordination and purple teaming
- Finish with timed practice sets under exam conditions
Because the exam runs about two hours for 100 questions, you have roughly a minute and a bit per item. Time yourself on practice sets so the pacing feels natural before test day. A one-page recap of the highest-yield definitions, like our C)IHE cheat sheet, is useful in the final days, and the practice tests let you rehearse the multiple-choice format.
Renewal: Three Years, 60 CEUs and the Dedicated Policy
Under the current dedicated renewal policy, the certification is valid for three years. Renewal calls for 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee, whose amount was not verified.
You may encounter older recertification wording in the course PDFs referencing a retake of the current exam and 20 CEUs per year. For current administration, rely on the dedicated renewal policy rather than combining the two: do not assume you must both retake the exam and earn annual CEUs. Also keep terminology straight, since CEUs are a maintenance requirement and are not exam weights. Likewise, the 40 CEUs attached to the five-day class are a training value, unrelated to how the exam is scored.
Where the Credential Fits in a Career
Incident handling skills map to roles such as security analyst, SOC team member, incident responder, and the team leads and managers who stand up and run response programs. The credential signals familiarity with the full lifecycle and with the organizational side of response, which is relevant wherever a team must formalize how it reacts to security events. For role-oriented detail, see C)IHE jobs.
Compensation depends heavily on region, seniority and employer, and no verified figures are supplied here, so we will not quote any. If earning potential is central to your decision, our salary guide and the ROI analysis frame the question qualitatively. The most reliable value comes from pairing the credential with hands-on experience: the exam tests knowledge, but employers hire for demonstrated judgment.
Frequently Asked Questions
The reviewed official material states 100 multiple-choice questions over approximately two hours, with a minimum passing score of 70%. The split between scored and unscored items is not stated.
No. They are the substantive modules of the linked course outline, presented as unweighted preparation scope. No official percentages or largest-weighted domain are published, so allocate study time across all twelve.
No. Course purchase is not required to buy the exam. The class is optional preparation, and a combo that bundles the exam with a simulator and guide was indexed at USD $500 on sale, with other pricing details unverified.
The current linked outline describes the older four-phase NIST 800-61 model and bears version string vs.922021. NIST Revision 3 was published April 3, 2025, but Mile2's adoption of it was not verified.
Under the dedicated renewal policy it is valid for three years. Renewal requires 60 qualifying CEUs, agreement to policies and ethics, and the applicable renewal fee, the amount of which was not verified.