C)IHE logo
Focused certification exam prep
Start practice

C)IHE Training

TL;DR
  • C)IHE training from Mile2 spans twelve substantive modules, plus a Module 00 introduction that is not counted as content.
  • The exam is 100 multiple-choice questions in about two hours, with a 70% minimum to pass.
  • Buying the course is not required to buy the exam; the exam combo bundles exam, simulator and guide.
  • The five-day class and 40 CEUs are course values, not exam length or scoring weights.

What C)IHE Training Actually Covers

The Certified Incident Handling Engineer (C)IHE) from Mile2 is built around a structured, process-oriented course. Unlike tool-centric security credentials, the training emphasizes how organizations create, staff and run an incident handling capability: policies, team models, services, preparation, detection, containment, recovery, lessons learned and information sharing. If you are weighing C)IHE training options, understand first that the curriculum rewards candidates who think like program builders as much as responders.

The course outline lists a Module 00 introduction followed by twelve substantive modules. Those twelve modules are the preparation scope used throughout this article. They are presented in the published outline as an unweighted sequence, so treat them as a study map, not as an official exam blueprint with percentages attached. For a deeper walk through each area, see the C)IHE exam domains guide.

Why the distinction matters: The published material does not state official percentages or identify a "largest" domain. Any weighting you see in a study plan, including ours, is editorial emphasis for practice allocation, not an official exam fact.

Course Values vs. Exam Facts

Candidates often blur what the class delivers with what the exam measures. Keep these separate:

ItemBelongs ToWhat It Means
Five-day classCourseDelivery length of the instructor-led training, not exam duration
40 CEUsCourseCredit value of the class, not a scoring weight
100 multiple-choice questionsExamQuestion count; the scored/unscored split is not stated
Approximately 2 hoursExamTesting window
70% minimumExamPassing threshold
Cyber Range exercisesCourseHands-on training support; no practical exam component is established

Understanding this split keeps your expectations realistic. You are preparing for a multiple-choice exam delivered online through the Mile2 Learning Management System, and the class is one route to the knowledge, not the exam itself. The details on thresholds are covered in the C)IHE passing score article.

Modules 01 to 05: Building the Incident Handling Foundation

The first five modules establish vocabulary, structure and recommendations. They are conceptual, which makes them easy to underestimate and common sources of scenario questions.

Module 01: Incident Handling Explained

This module defines what an incident is, what incident handling is, and how incident handling differs from incident response.

  • The incident response process and why a formal plan is justified (the outline gives seven reasons)
  • How to build an effective response team and what to weigh when creating one
  • Practical tips for response team members

Module 02: Incident Response Policy, Plan and Procedure Creation

Know the hierarchy: policy sets authority and scope, the plan sets the roadmap, and procedures supply step-by-step execution.

  • Distinguishing policy, plan and procedure in scenario wording
  • Sharing information with outside parties and the judgment it requires

Module 03: Incident Response Team Structure

Team models, how to select among them, the personnel involved, and the dependencies an incident team has within an organization.

  • Matching a team model to organizational size and distribution
  • Recognizing cross-department dependencies that affect response speed

Module 04: Incident Response Team Services

The services a team offers beyond firefighting: intrusion detection, advisory distribution, education and awareness, and information sharing.

Module 05: Incident Response Recommendations

Establishing a formal incident response capability, establishing information sharing capabilities, and building the team itself.

Expect questions that ask you to choose the best organizational decision rather than recall a definition. The C)IHE study guide lays out how to turn these foundations into a revision routine.

Modules 06 to 09: The Incident Lifecycle in Practice

Here the course moves from structure to action. One quirk worth knowing: the issuer prints the Preparation module as "Chapter 06" within the same sequential list, even though every other entry says "Module." It is the same sequential course, and this article treats it as the sixth substantive area.

Preparation (printed as Chapter 06)

The proactive side of incident handling.

  • Threat hunting and threat analysis frameworks
  • Tools and toolkits for responders
  • Policy and procedures that support readiness
  • Preventing incidents before they start

Module 07: Detection and Analysis

Often the richest source of scenario questions because it demands judgment under ambiguity.

  • Attack vectors and the signs of an incident
  • Sources of precursors and indicators, and the difference between the two
  • Incident analysis, documentation, prioritization and notification

Module 08: Containment, Eradication and Recovery

  • Selecting the right containment strategy for the situation
  • Gathering and handling evidence properly
  • Identifying the attacking hosts
  • Eradication and recovery sequencing

Module 09: Post Incident Activity

  • Lessons learned and how to run them productively
  • Using collected incident data
  • Evidence retention
Pattern to watch: Several questions hinge on ordering. Containment strategy choices depend on evidence preservation needs, and eradication should not begin before you understand scope. When two answers both sound reasonable, ask which one protects evidence and limits spread first.

Modules 10 to 12: Checklists, Recommendations and Coordination

Module 10: Incident Handling Checklist

Why checklists matter and how to build them, so responders stay consistent under pressure.

Module 11: Incident Handling Recommendations

Consolidated recommendations plus implementing threat intelligence into the handling program.

Module 12: Coordination and Information Sharing

  • Coordination across teams and organizations
  • Purple teaming
  • Information sharing techniques, including granular information sharing
  • Sharing recommendations

Because these closing modules reuse earlier themes, they reward cross-referencing. Information sharing appears in the services module, the recommendations module and again here, each time with a slightly different lens. Review all three together. Our C)IHE cheat sheet condenses these repeating ideas into a quick review format.

The NIST Model and Course Version Caveat

The current linked outline carries a version string of vs. 922021 and describes the older four-phase NIST 800-61 incident response model. NIST published Revision 3 on April 3, 2025, but Mile2 adoption of that revision was not verified in the reviewed materials.

Key Takeaway

Study the four-phase model as the course presents it, and treat it as historical course content rather than proof that the exam follows NIST Revision 3. If you want broader professional awareness, read about the newer revision separately, but anchor your exam preparation to the Mile2 outline.

Experience to Bring Before You Start

Mile2 suggests roughly 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions, and the reviewed material did not verify a mandatory degree or a required number of references. Course purchase is not required to buy the exam. For a fuller discussion, read the C)IHE requirements breakdown.

In practical terms, the Linux and TCP/IP background matters most in the detection, analysis and containment material, where you are expected to reason about traffic, hosts and logs.

Cyber Range Labs: Useful, but Not a Practical Exam

The training includes Cyber Range exercises that support hands-on learning. Do not read that as evidence of a practical certification component. The exam described in the reviewed material is 100 multiple-choice questions; Cyber Range work reinforces understanding but is not established as an exam format. Use labs to make the process modules concrete, then confirm recall with practice questions.

Exam Mechanics and Cost

DetailWhat Is Documented
Format100 multiple-choice questions
DurationApproximately 2 hours
Passing score70% minimum
DeliveryOnline through the Mile2 Learning Management System
Indexed Exam ComboUSD $500 sale / $795 original, including exam, simulator and guide
Not verifiedBare-exam fee, member/nonmember pricing, taxes, sale duration, open-book/calculator rules, remote-proctoring and adaptive behavior

Because several rules are unverified, confirm them directly inside your Mile2 account before scheduling. The candidate pass rate is not publicly disclosed in the reviewed official material, so be wary of any specific figure you encounter; see what the data shows on the C)IHE pass rate. For budgeting, the C)IHE certification cost article explains how to compare the combo against separate purchases, and C)IHE exam dates covers scheduling.

Sequencing the Twelve Modules

If you are self-pacing alongside the class, order matters more than any generic technique. One reasonable arrangement, which is editorial rather than official:

Week 1

Foundations

  • Incident Handling Explained, Policy/Plan/Procedure, Team Structure
  • Lock in the policy versus plan versus procedure distinction
Week 2

Team Services and Preparation

  • Team Services, Recommendations, Preparation
  • Pair threat hunting and analysis frameworks with the tools material
Week 3

The Response Core

  • Detection and Analysis, Containment/Eradication/Recovery, Post Incident Activity
  • Spend the most practice time here, since scenario questions concentrate on process decisions
Week 4

Consolidation

  • Checklists, Handling Recommendations, Coordination and Information Sharing
  • Finish with timed 100-question practice sets on the main practice test site

Whether the exam feels demanding depends on your background; the difficulty guide discusses what tends to trip candidates up.

After Training: Renewal and Career Context

Certification validity is three years under the current dedicated renewal policy, which calls for 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee (the amount was not verified). Older course PDFs contain different wording about retaking the current exam and earning 20 CEUs per year. For current administration, follow the dedicated renewal policy rather than combining both sets of requirements, and remember CEUs are renewal credits, never exam weights.

On the career side, the credential suits roles built around response processes: incident handlers, SOC analysts moving toward team leadership, and security staff who must formalize response programs. For realistic expectations, see C)IHE jobs, and for value judgments, whether the certification is worth it.

Frequently Asked Questions

Do I have to take the Mile2 course to sit the C)IHE exam?

No. Course purchase is not required to buy the exam. The indexed Exam Combo bundles the exam, simulator and guide, and the course is a separate route to the material.

How many modules does the C)IHE course have?

The outline lists a Module 00 introduction plus twelve substantive modules, from Incident Handling Explained through Coordination and Information Sharing. Module 00 is not counted as content.

Are the twelve modules weighted on the exam?

Not in the reviewed official material. They are unweighted preparation scope, and no official percentages or largest-weighted domain are published.

Is there a hands-on practical portion on the exam?

The documented exam is 100 multiple-choice questions. Cyber Range exercises support training but do not establish a practical certification exam component.

Does the training teach the newest NIST incident response guidance?

The linked outline (vs. 922021) describes the older four-phase NIST 800-61 model. NIST Revision 3 was published April 3, 2025, but Mile2 adoption was not verified, so study the model as the course presents it.

Ready to pass your C)IHE exam?

Put this into practice with free C)IHE questions across every exam domain.