C)IHE logo
Focused certification exam prep
Start practice

C)IHE Certification

TL;DR
  • C)IHE is Mile2's Certified Incident Handling Engineer exam: 100 multiple-choice questions, about two hours, 70% minimum to pass.
  • The twelve course modules are unweighted preparation scope, not an official weighted exam blueprint.
  • The current linked outline carries version string vs.922021 and teaches the older four-phase NIST 800-61 model.
  • Certification lasts three years and renewal requires 60 qualifying CEUs plus agreement to policies and ethics.

What the Certified Incident Handling Engineer Credential Is

The Certified Incident Handling Engineer credential, abbreviated C)IHE, is a Mile2 certification built around the full lifecycle of handling a security incident: building the capability, preparing, detecting, containing, recovering and learning from what happened. It is not a general security survey. Its subject matter is the organizational and procedural machinery of incident response, covering policies, team structures, services, checklists and coordination with outside parties, alongside the technical activity of analyzing and containing an incident.

If you are still orienting yourself on the terminology, our explainers on what C)IHE certification is and what C)IHE stands for cover the basics. This article goes deeper into how the exam is structured, what the preparation scope contains and how to sequence your study. If you want to test yourself as you read, the C)IHE practice tests are the fastest way to find your weak spots.

Identity check: Several unrelated credentials share a similar acronym. Everything on this page concerns Mile2's Certified Incident Handling Engineer only. Fees, formats and content from any other certification do not apply here.

Exam Format, Registration and Pricing Mechanics

Testing is delivered online through the Mile2 Learning Management System. The published parameters are straightforward:

AttributeWhat the reviewed official material states
Question count100 multiple-choice questions
DurationApproximately 2 hours
Minimum passing score70%
DeliveryOnline via the Mile2 Learning Management System
Scored vs. unscored itemsSplit not stated
Candidate pass rateNot publicly disclosed in the reviewed official material
Open-book, calculator, remote-proctoring and adaptive rulesNot verified

That last row matters. Because the reviewed material does not confirm proctoring or open-book rules, confirm them directly inside your Mile2 account before exam day rather than assuming. For the specifics of scoring, see our breakdown of the C)IHE passing score, and for what is and is not known about outcomes, read the discussion in C)IHE pass rate.

What the exam costs

The official indexed Exam Combo, which includes the exam, a simulator and a guide, was listed at USD $500 on sale against an original price of $795. Several details remain unverified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes and how long the sale price runs. Treat the combo figure as a reference point and confirm the live price at checkout. Our C)IHE certification cost guide tracks the pricing picture in more detail.

One useful fact: purchasing the course is not required to buy the exam. Candidates who already have incident response experience can go straight to the exam, while those who prefer structured instruction can take the class. The five-day class and its 40 CEUs are course values; they describe the training, not the exam's duration or any scoring weight.

The Twelve Preparation Areas, Module by Module

The preparation scope maps to the twelve substantive modules of the currently linked Mile2 course outline. Module 00 is a course introduction and is not counted. Crucially, these are unweighted course preparation headings, not an official weighted or exhaustive examination blueprint. No official percentages are published, so no domain can honestly be called the largest. Any allocation of your study hours is editorial judgment, not an insider breakdown. For a longer treatment, see C)IHE exam domains: a complete guide to all 12 content areas.

Domain 1: Incident Handling Explained

The conceptual foundation. You must be able to define an incident, distinguish incident handling from incident response, and describe the response process end to end.

  • What is an incident, and what is incident handling
  • The difference between IH and IR
  • Seven reasons to put together an incident response plan
  • How to build an effective team, considerations for creating one, and tips for team members

Domain 2: Incident Response Policy, Plan and Procedure Creation

Expect questions that test whether you can tell the three documents apart and know what belongs in each.

  • Incident response policy versus plan versus procedures
  • Sharing information with outside parties

Domain 3: Incident Response Team Structure

Organizational design questions: which team model suits which organization and why.

  • Team models and team model selection
  • Incident response personnel
  • Dependencies within organizations

Domain 4: Incident Response Team Services

What a team actually offers its constituency beyond reacting to alerts.

  • Intrusion detection
  • Advisory distribution
  • Education and awareness
  • Information sharing

Domain 5: Incident Response Recommendations

Program-level guidance: establishing a formal capability, establishing information sharing capabilities and building the team.

Domain 6: Preparation

The issuer prints this one as "Chapter 06" within the same sequential list, a small quirk worth knowing so you are not confused by the labeling. It is the most hands-on of the planning modules.

  • Threat hunting and threat analysis frameworks
  • Tools and toolkits
  • Policy and procedures
  • Preventing incidents

Domain 7: Detection and Analysis

The operational core. Know how incidents present themselves and how analysts work them.

  • Attack vectors and signs of an incident
  • Sources of precursors and indicators
  • Incident analysis, documentation, prioritization and notification

Domain 8: Containment, Eradication and Recovery

Decision-driven material: choosing a containment strategy, handling evidence properly, identifying attacking hosts, then eradicating and recovering.

Domain 9: Post Incident Activity

Lessons learned, using collected incident data and evidence retention.

Domain 10: Incident Handling Checklist

Why checklists matter and how to build them so responders act consistently under pressure.

Domain 11: Incident Handling Recommendations

Consolidated recommendations, including implementing threat intelligence.

Domain 12: Coordination and Information Sharing

Coordination, purple teaming, information sharing techniques, granular information sharing and sharing recommendations.

Reading the list correctly: Notice how much of the scope is planning, structure and coordination rather than packet-level forensics. Candidates who prepare only on technical analysis tend to under-prepare Domains 1 through 5 and 10 through 12, which are about policy, people and process.

The NIST Version Question: What the Outline Actually Says

This is a point where careful reading pays off. The current linked outline bears the version string vs.922021 and describes the older four-phase NIST 800-61 model. NIST published Revision 3 on April 3, 2025, but whether Mile2 has adopted it into the C)IHE course or exam was not verified. The four-phase model in the outline is historical course content; it is not evidence that Mile2 has moved to Revision 3.

The practical takeaway is to study the phase structure as the outline presents it, and not to assume that newer NIST framing will appear on your exam. If you also read Revision 3 for professional development, keep it clearly separate from your exam preparation, and avoid answering a C)IHE question using vocabulary the course never taught. Our C)IHE study guide reinforces this by anchoring preparation to the published outline.

Key Takeaway

Prepare from the outline Mile2 actually publishes. Treat the four-phase NIST 800-61 content as the working model for the exam, and verify any change in the course materials you receive.

Prerequisites and Who Should Sit This Exam

Mile2 suggests about 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions rather than hard gates: no mandatory degree and no reference count was verified. Our C)IHE requirements page walks through qualification in more depth.

In practice, the ideal candidate is someone who already touches security operations: a SOC analyst moving toward a lead role, a sysadmin who gets pulled into every outage, or a security generalist being asked to write the organization's first response plan. Because the scope is as much about building a response capability as executing one, managers and team leads can benefit as well.

Is it a hard exam?

Difficulty is subjective and no pass rate is published, so honest answers depend on your background. Candidates with real response experience will find the process vocabulary familiar; those without it may find the policy-versus-plan-versus-procedure distinctions and team-model questions less intuitive than the technical ones. See how hard the C)IHE exam is for a fuller discussion.

Sequencing Your Preparation Around the Twelve Areas

Since the exam has no published domain weights, spread your effort across all twelve areas instead of betting on a guess about which dominates. A sensible order follows the incident lifecycle, because later modules build on earlier vocabulary. The allocation below is editorial, not an official weighting.

Week 1

Foundations and Governance

  • Domains 1 and 2: definitions, IH versus IR, policy versus plan versus procedure
  • Write one-line distinctions you can recall instantly
Week 2

Team and Services

  • Domains 3, 4 and 5: team models, personnel, services and program recommendations
  • Practice matching a scenario to the most suitable team model
Week 3

Preparation, Detection and Analysis

  • Domains 6 and 7: threat hunting, frameworks, toolkits, indicators and prioritization
  • Spend extra time here if you lack hands-on SOC experience
Week 4

Response, Recovery and Review

  • Domains 8 and 9: containment strategy, evidence handling, recovery and lessons learned
  • Domains 10, 11 and 12: checklists, recommendations, coordination and purple teaming
  • Finish with timed practice sets under exam conditions

Because the exam runs about two hours for 100 questions, you have roughly a minute and a bit per item. Time yourself on practice sets so the pacing feels natural before test day. A one-page recap of the highest-yield definitions, like our C)IHE cheat sheet, is useful in the final days, and the practice tests let you rehearse the multiple-choice format.

Renewal: Three Years, 60 CEUs and the Dedicated Policy

Under the current dedicated renewal policy, the certification is valid for three years. Renewal calls for 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee, whose amount was not verified.

You may encounter older recertification wording in the course PDFs referencing a retake of the current exam and 20 CEUs per year. For current administration, rely on the dedicated renewal policy rather than combining the two: do not assume you must both retake the exam and earn annual CEUs. Also keep terminology straight, since CEUs are a maintenance requirement and are not exam weights. Likewise, the 40 CEUs attached to the five-day class are a training value, unrelated to how the exam is scored.

Cyber Range clarification: Mile2's Cyber Range exercises are part of training. They do not establish that the certification exam contains a practical, lab-based component. The exam as described in the reviewed material is multiple-choice.

Where the Credential Fits in a Career

Incident handling skills map to roles such as security analyst, SOC team member, incident responder, and the team leads and managers who stand up and run response programs. The credential signals familiarity with the full lifecycle and with the organizational side of response, which is relevant wherever a team must formalize how it reacts to security events. For role-oriented detail, see C)IHE jobs.

Compensation depends heavily on region, seniority and employer, and no verified figures are supplied here, so we will not quote any. If earning potential is central to your decision, our salary guide and the ROI analysis frame the question qualitatively. The most reliable value comes from pairing the credential with hands-on experience: the exam tests knowledge, but employers hire for demonstrated judgment.

Frequently Asked Questions

How many questions are on the C)IHE exam?

The reviewed official material states 100 multiple-choice questions over approximately two hours, with a minimum passing score of 70%. The split between scored and unscored items is not stated.

Are the twelve modules official exam domains with percentages?

No. They are the substantive modules of the linked course outline, presented as unweighted preparation scope. No official percentages or largest-weighted domain are published, so allocate study time across all twelve.

Do I have to buy the course to take the exam?

No. Course purchase is not required to buy the exam. The class is optional preparation, and a combo that bundles the exam with a simulator and guide was indexed at USD $500 on sale, with other pricing details unverified.

Does the exam use the latest NIST incident response guidance?

The current linked outline describes the older four-phase NIST 800-61 model and bears version string vs.922021. NIST Revision 3 was published April 3, 2025, but Mile2's adoption of it was not verified.

How long does the certification last, and how do I renew?

Under the dedicated renewal policy it is valid for three years. Renewal requires 60 qualifying CEUs, agreement to policies and ethics, and the applicable renewal fee, the amount of which was not verified.

Ready to pass your C)IHE exam?

Put this into practice with free C)IHE questions across every exam domain.