- What C)IHE Training Actually Covers
- Course Values vs. Exam Facts
- Modules 01 to 05: Building the Incident Handling Foundation
- Modules 06 to 09: The Incident Lifecycle in Practice
- Modules 10 to 12: Checklists, Recommendations and Coordination
- The NIST Model and Course Version Caveat
- Experience to Bring Before You Start
- Cyber Range Labs: Useful, but Not a Practical Exam
- Exam Mechanics and Cost
- Sequencing the Twelve Modules
- After Training: Renewal and Career Context
- Frequently Asked Questions
- C)IHE training from Mile2 spans twelve substantive modules, plus a Module 00 introduction that is not counted as content.
- The exam is 100 multiple-choice questions in about two hours, with a 70% minimum to pass.
- Buying the course is not required to buy the exam; the exam combo bundles exam, simulator and guide.
- The five-day class and 40 CEUs are course values, not exam length or scoring weights.
What C)IHE Training Actually Covers
The Certified Incident Handling Engineer (C)IHE) from Mile2 is built around a structured, process-oriented course. Unlike tool-centric security credentials, the training emphasizes how organizations create, staff and run an incident handling capability: policies, team models, services, preparation, detection, containment, recovery, lessons learned and information sharing. If you are weighing C)IHE training options, understand first that the curriculum rewards candidates who think like program builders as much as responders.
The course outline lists a Module 00 introduction followed by twelve substantive modules. Those twelve modules are the preparation scope used throughout this article. They are presented in the published outline as an unweighted sequence, so treat them as a study map, not as an official exam blueprint with percentages attached. For a deeper walk through each area, see the C)IHE exam domains guide.
Course Values vs. Exam Facts
Candidates often blur what the class delivers with what the exam measures. Keep these separate:
| Item | Belongs To | What It Means |
|---|---|---|
| Five-day class | Course | Delivery length of the instructor-led training, not exam duration |
| 40 CEUs | Course | Credit value of the class, not a scoring weight |
| 100 multiple-choice questions | Exam | Question count; the scored/unscored split is not stated |
| Approximately 2 hours | Exam | Testing window |
| 70% minimum | Exam | Passing threshold |
| Cyber Range exercises | Course | Hands-on training support; no practical exam component is established |
Understanding this split keeps your expectations realistic. You are preparing for a multiple-choice exam delivered online through the Mile2 Learning Management System, and the class is one route to the knowledge, not the exam itself. The details on thresholds are covered in the C)IHE passing score article.
Modules 01 to 05: Building the Incident Handling Foundation
The first five modules establish vocabulary, structure and recommendations. They are conceptual, which makes them easy to underestimate and common sources of scenario questions.
Module 01: Incident Handling Explained
This module defines what an incident is, what incident handling is, and how incident handling differs from incident response.
- The incident response process and why a formal plan is justified (the outline gives seven reasons)
- How to build an effective response team and what to weigh when creating one
- Practical tips for response team members
Module 02: Incident Response Policy, Plan and Procedure Creation
Know the hierarchy: policy sets authority and scope, the plan sets the roadmap, and procedures supply step-by-step execution.
- Distinguishing policy, plan and procedure in scenario wording
- Sharing information with outside parties and the judgment it requires
Module 03: Incident Response Team Structure
Team models, how to select among them, the personnel involved, and the dependencies an incident team has within an organization.
- Matching a team model to organizational size and distribution
- Recognizing cross-department dependencies that affect response speed
Module 04: Incident Response Team Services
The services a team offers beyond firefighting: intrusion detection, advisory distribution, education and awareness, and information sharing.
Module 05: Incident Response Recommendations
Establishing a formal incident response capability, establishing information sharing capabilities, and building the team itself.
Expect questions that ask you to choose the best organizational decision rather than recall a definition. The C)IHE study guide lays out how to turn these foundations into a revision routine.
Modules 06 to 09: The Incident Lifecycle in Practice
Here the course moves from structure to action. One quirk worth knowing: the issuer prints the Preparation module as "Chapter 06" within the same sequential list, even though every other entry says "Module." It is the same sequential course, and this article treats it as the sixth substantive area.
Preparation (printed as Chapter 06)
The proactive side of incident handling.
- Threat hunting and threat analysis frameworks
- Tools and toolkits for responders
- Policy and procedures that support readiness
- Preventing incidents before they start
Module 07: Detection and Analysis
Often the richest source of scenario questions because it demands judgment under ambiguity.
- Attack vectors and the signs of an incident
- Sources of precursors and indicators, and the difference between the two
- Incident analysis, documentation, prioritization and notification
Module 08: Containment, Eradication and Recovery
- Selecting the right containment strategy for the situation
- Gathering and handling evidence properly
- Identifying the attacking hosts
- Eradication and recovery sequencing
Module 09: Post Incident Activity
- Lessons learned and how to run them productively
- Using collected incident data
- Evidence retention
Modules 10 to 12: Checklists, Recommendations and Coordination
Module 10: Incident Handling Checklist
Why checklists matter and how to build them, so responders stay consistent under pressure.
Module 11: Incident Handling Recommendations
Consolidated recommendations plus implementing threat intelligence into the handling program.
Module 12: Coordination and Information Sharing
- Coordination across teams and organizations
- Purple teaming
- Information sharing techniques, including granular information sharing
- Sharing recommendations
Because these closing modules reuse earlier themes, they reward cross-referencing. Information sharing appears in the services module, the recommendations module and again here, each time with a slightly different lens. Review all three together. Our C)IHE cheat sheet condenses these repeating ideas into a quick review format.
The NIST Model and Course Version Caveat
The current linked outline carries a version string of vs. 922021 and describes the older four-phase NIST 800-61 incident response model. NIST published Revision 3 on April 3, 2025, but Mile2 adoption of that revision was not verified in the reviewed materials.
Key Takeaway
Study the four-phase model as the course presents it, and treat it as historical course content rather than proof that the exam follows NIST Revision 3. If you want broader professional awareness, read about the newer revision separately, but anchor your exam preparation to the Mile2 outline.
Experience to Bring Before You Start
Mile2 suggests roughly 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions, and the reviewed material did not verify a mandatory degree or a required number of references. Course purchase is not required to buy the exam. For a fuller discussion, read the C)IHE requirements breakdown.
In practical terms, the Linux and TCP/IP background matters most in the detection, analysis and containment material, where you are expected to reason about traffic, hosts and logs.
Cyber Range Labs: Useful, but Not a Practical Exam
The training includes Cyber Range exercises that support hands-on learning. Do not read that as evidence of a practical certification component. The exam described in the reviewed material is 100 multiple-choice questions; Cyber Range work reinforces understanding but is not established as an exam format. Use labs to make the process modules concrete, then confirm recall with practice questions.
Exam Mechanics and Cost
| Detail | What Is Documented |
|---|---|
| Format | 100 multiple-choice questions |
| Duration | Approximately 2 hours |
| Passing score | 70% minimum |
| Delivery | Online through the Mile2 Learning Management System |
| Indexed Exam Combo | USD $500 sale / $795 original, including exam, simulator and guide |
| Not verified | Bare-exam fee, member/nonmember pricing, taxes, sale duration, open-book/calculator rules, remote-proctoring and adaptive behavior |
Because several rules are unverified, confirm them directly inside your Mile2 account before scheduling. The candidate pass rate is not publicly disclosed in the reviewed official material, so be wary of any specific figure you encounter; see what the data shows on the C)IHE pass rate. For budgeting, the C)IHE certification cost article explains how to compare the combo against separate purchases, and C)IHE exam dates covers scheduling.
Sequencing the Twelve Modules
If you are self-pacing alongside the class, order matters more than any generic technique. One reasonable arrangement, which is editorial rather than official:
Foundations
- Incident Handling Explained, Policy/Plan/Procedure, Team Structure
- Lock in the policy versus plan versus procedure distinction
Team Services and Preparation
- Team Services, Recommendations, Preparation
- Pair threat hunting and analysis frameworks with the tools material
The Response Core
- Detection and Analysis, Containment/Eradication/Recovery, Post Incident Activity
- Spend the most practice time here, since scenario questions concentrate on process decisions
Consolidation
- Checklists, Handling Recommendations, Coordination and Information Sharing
- Finish with timed 100-question practice sets on the main practice test site
Whether the exam feels demanding depends on your background; the difficulty guide discusses what tends to trip candidates up.
After Training: Renewal and Career Context
Certification validity is three years under the current dedicated renewal policy, which calls for 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee (the amount was not verified). Older course PDFs contain different wording about retaking the current exam and earning 20 CEUs per year. For current administration, follow the dedicated renewal policy rather than combining both sets of requirements, and remember CEUs are renewal credits, never exam weights.
On the career side, the credential suits roles built around response processes: incident handlers, SOC analysts moving toward team leadership, and security staff who must formalize response programs. For realistic expectations, see C)IHE jobs, and for value judgments, whether the certification is worth it.
Frequently Asked Questions
No. Course purchase is not required to buy the exam. The indexed Exam Combo bundles the exam, simulator and guide, and the course is a separate route to the material.
The outline lists a Module 00 introduction plus twelve substantive modules, from Incident Handling Explained through Coordination and Information Sharing. Module 00 is not counted as content.
Not in the reviewed official material. They are unweighted preparation scope, and no official percentages or largest-weighted domain are published.
The documented exam is 100 multiple-choice questions. Cyber Range exercises support training but do not establish a practical certification exam component.
The linked outline (vs. 922021) describes the older four-phase NIST 800-61 model. NIST Revision 3 was published April 3, 2025, but Mile2 adoption was not verified, so study the model as the course presents it.