C)IHE logo
Focused certification exam prep
Start practice

What Is A C)IHE?

TL;DR
  • C)IHE stands for Certified Incident Handling Engineer, a Mile2 credential tested online through the Mile2 Learning Management System.
  • The exam is 100 multiple-choice questions in about two hours, with a 70% minimum to pass.
  • Twelve course modules form the preparation scope, but they are unweighted and not an official exam blueprint.
  • Mile2 suggests 12 months of network-technology experience, TCP/IP knowledge and essential Linux skills before sitting.

The Short Answer: Who Issues the C)IHE and What It Proves

A C)IHE is a Certified Incident Handling Engineer: a professional who has passed the Mile2 certification exam covering how organizations prepare for, detect, contain, eradicate, recover from and learn from security incidents. The credential is issued by Mile2, and the exam is delivered online through the Mile2 Learning Management System.

The acronym is easy to confuse. Several unrelated credentials in other fields share similar letters, so when you research this certification, confirm that any source you read actually describes Mile2's Certified Incident Handling Engineer. Everything on this page refers only to that credential. If you want a quick orientation on the naming itself, see What Does C)IHE Stand For? and C)IHE Meaning.

What does the certification signal? It shows that you understand incident handling as an organizational capability, not just a technical reaction. The preparation material spends as much time on policy, team structure, information sharing and checklists as it does on detection and containment. That emphasis shapes the kind of professional the credential suits: someone who must build or run an incident response function, not only operate a single tool.

Incident Handling Defined: The Ground the Credential Covers

The course begins by establishing vocabulary, and the exam expects you to use it precisely. Module 1 walks through what an incident is, what incident handling is, and how incident handling differs from incident response. It also covers the incident response process, seven reasons an organization needs a formal incident response plan, how to build an effective incident response team, considerations when creating that team, and tips for team members.

Why the definitions matter: Multiple-choice questions often hinge on a distinction rather than a procedure, such as telling an event from an incident, or separating the broader handling discipline from the response activity inside it. Candidates who skim the opening module tend to lose easy points on terminology.

From that foundation the material moves in a roughly chronological arc: build the policy and plan, structure the team, define its services, prepare, detect, contain, recover, review and share what you learned. Think of the twelve modules as the lifecycle of a mature incident response program rather than a loose list of topics.

How the Exam Works: Format, Delivery and Scoring

The published facts are straightforward:

AttributeC)IHE Detail
IssuerMile2
DeliveryOnline through the Mile2 Learning Management System
Question count100 multiple-choice questions
Time allowedApproximately 2 hours
Passing grade70% minimum
Scored vs. unscored splitNot stated in reviewed official material
Practical componentNone established; Cyber Range training does not make the certification exam practical

Several details are not publicly specified in the reviewed material, and it is better to say so than to guess. Rules on open-book use, calculators, remote proctoring and adaptive question delivery were not verified, and the candidate pass rate is not publicly disclosed. Check the current candidate instructions inside your Mile2 account before test day. For the numbers behind the threshold, our C)IHE passing score guide and pass rate analysis explain what is and is not known.

Because the format is multiple choice with a 70% bar, the exam rewards broad, accurate recall and good judgment on scenario-style wording rather than hands-on lab speed. The course does include Cyber Range exercises, and the class itself runs five days and carries 40 CEUs, but those are course values. They are not exam duration, not scoring weights, and not evidence of a practical exam.

Key Takeaway

Do not confuse the five-day class and its 40 CEUs with the exam. The exam is a separate 100-question, roughly two-hour, multiple-choice test with a 70% passing grade.

If you are wondering how demanding that feels in practice, read How Hard Is the C)IHE Exam? for a qualitative breakdown.

The Twelve Preparation Areas, Grouped by Purpose

The current-linked Mile2 outline lists twelve substantive modules after a course introduction. We treat them as twelve preparation areas. Mile2 does not publish percentage weights for them, so no area can honestly be called the largest. Any allocation of your study time is an editorial judgment, not an official ratio. For a deeper walk-through, see our complete guide to all 12 content areas.

Building the capability (Domains 1 to 5)

Domain 1: Incident Handling Explained

Definitions, the incident response process, and the case for a formal plan and team.

  • Incident versus event, and incident handling versus incident response
  • Seven reasons to put an incident response plan together
  • Considerations and tips for building the response team

Domain 2: Incident Response Policy, Plan and Procedure Creation

How the three documents differ and how they relate.

  • Policy as the authority statement; plan as the roadmap; procedures as the step-level detail
  • Sharing information with outside parties

Domain 3: Incident Response Team Structure

Team models, how to choose one, the personnel involved and organizational dependencies.

  • Comparing team models and the factors behind model selection
  • Dependencies the team has on other groups inside the organization

Domain 4: Incident Response Team Services

What a response team actually offers its constituency.

  • Intrusion detection, advisory distribution, education and awareness, information sharing

Domain 5: Incident Response Recommendations

Consolidated guidance on standing up the function.

  • Establish a formal incident response capability
  • Establish information sharing capabilities and build the team

Running the lifecycle (Domains 6 to 9)

Domain 6: Preparation

Published as Chapter 06 in the issuer's sequential list, this area covers readiness work before anything goes wrong.

  • Threat hunting and threat analysis frameworks
  • Tools and toolkits, policy, procedures and preventing incidents

Domain 7: Detection and Analysis

Recognizing, validating and ranking incidents.

  • Attack vectors, signs of an incident, and sources of precursors and indicators
  • Incident analysis, documentation, prioritization and notification

Domain 8: Containment, Eradication and Recovery

Stopping damage and restoring service in a defensible way.

  • Selecting the right containment strategy
  • Gathering and handling evidence, and identifying attacking hosts
  • Eradication and recovery

Domain 9: Post Incident Activity

Turning an incident into organizational learning.

  • Lessons learned, using collected incident data and evidence retention

Sustaining and sharing (Domains 10 to 12)

Domain 10: Incident Handling Checklist

Why checklists matter under pressure and how to build them.

Domain 11: Incident Handling Recommendations

Closing recommendations, including how to implement threat intelligence.

Domain 12: Coordination and Information Sharing

Working across teams and organizations.

  • Coordination, purple teaming and information sharing techniques
  • Granular information sharing and sharing recommendations

Two patterns stand out. First, a large share of the outline is about program design and governance, so candidates with only a technical background should budget real time for Domains 2 through 5. Second, several themes recur across modules, including information sharing in Domains 2, 4, 5 and 12, and evidence handling in Domains 8 and 9. Recurring themes are good candidates for cross-domain review.

A Note on the NIST 800-61 Model in the Course Outline

The current-linked outline bears the version string vs. 922021 and describes the older four-phase incident response model drawn from NIST 800-61. NIST published Revision 3 of that guidance on April 3, 2025, but whether Mile2 has adopted it into the C)IHE course has not been verified.

Preserve the distinction: The four-phase model is historical course content in the outline, not proof that Mile2 has moved to Revision 3. When you study, learn the model as the course presents it, and treat newer NIST material as useful professional context rather than assumed exam content unless Mile2 states otherwise.

This is a good example of why you should work from the official outline rather than from generic incident response articles. A source that teaches a different phase structure can quietly steer you toward answers the exam does not expect.

Registration and Fee Mechanics

Mile2 sells the exam in a few ways, and the verified pricing picture is narrower than many candidates expect. The official indexed Exam Combo is listed at a sale price of USD $500 against an original price of $795, and it includes the exam, a simulator and a guide. What has not been verified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Prices can change, so confirm everything at checkout.

Importantly, purchasing the course is not required to buy the exam. Self-directed candidates with the right background can register for the exam without sitting the five-day class. For a fuller breakdown and the reasoning behind each cost component, see C)IHE Certification Cost, and for logistics see C)IHE Exam Dates.

Who Should Sit the Exam and What You Should Already Know

Mile2 suggests about 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions rather than hard gates. No mandatory degree or reference count was verified in the reviewed material. Our C)IHE requirements article covers eligibility in more detail.

Why those prerequisites? Detection and analysis questions assume you can reason about traffic, hosts and logs. You do not need to be a senior forensic analyst, but you should be comfortable reading a scenario that mentions ports, protocols or a Linux host and understanding what an analyst would conclude from it.

  • Good fits: SOC analysts moving toward response roles, systems and network administrators drafted into incident duty, security team leads formalizing a response program, and compliance or risk staff who coordinate with responders.
  • Possible stretch: candidates with no networking background, who should shore up TCP/IP fundamentals before attempting Domain 7 content.

Where the Credential Fits in the Job Market

Because the content spans program design and operational response, the certification maps most naturally to roles where incident handling is part of the job description: security operations analysts, incident responders, CSIRT or CERT team members, security engineers and security managers building out a response capability. Organizations that value documented process, such as regulated industries, managed security providers and government-adjacent contractors, are the most natural audiences for a credential built around plans, policies and procedures.

We do not cite salary figures here, because none are verified for this credential in the reviewed sources. If you are weighing the career case, our guides on C)IHE jobs, the salary picture and whether the certification is worth it discuss the question qualitatively and in context.

Staying Certified: Renewal and CEUs

Under the current dedicated renewal policy, certification is valid for three years. Renewal requires 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee. The amount of that fee was not verified.

Watch for outdated wording: Older Mile2 course PDFs mention retaking the current exam and earning 20 CEUs per year. For current administration, rely on the dedicated renewal policy rather than stacking both requirements. Also remember that CEUs are a renewal currency, not an exam weighting. The 40 CEUs attached to the five-day class say nothing about how the exam is scored.

Sequencing Your Preparation Around C)IHE Content

Since Mile2 publishes no domain weights, a sensible plan spreads time across all twelve areas and then adds extra passes where your background is thin. The schedule below is an editorial suggestion, not an official allocation, and it can compress or stretch to fit your calendar. For a fuller method, see the C)IHE study guide.

Week 1

Vocabulary and program design

  • Domains 1 and 2: definitions, process, policy versus plan versus procedure
  • Build a one-page comparison of incident handling and incident response
Week 2

People and services

  • Domains 3, 4 and 5: team models, selection criteria, services and recommendations
  • Note how information sharing recurs across these modules
Week 3

The operational core

  • Domains 6 and 7: preparation, threat hunting, indicators, analysis and prioritization
  • Revisit TCP/IP and Linux basics if scenarios feel unfamiliar
Week 4

Response, review and sharing

  • Domains 8 to 12: containment, evidence, lessons learned, checklists, coordination and purple teaming
  • Finish with timed sets of 100 questions to rehearse the two-hour pace

Evidence handling, containment strategy selection and the policy-plan-procedure distinction are the kinds of topics that reward scenario practice. When you are ready to test yourself, work through realistic questions on the C)IHE practice test site, and use the C)IHE cheat sheet for a last-day review. For options beyond self-study, see C)IHE training.

Frequently Asked Questions

What does C)IHE stand for?

It stands for Certified Incident Handling Engineer, a certification issued by Mile2. It is distinct from other credentials that happen to share a similar acronym, so always confirm the issuer when researching.

How many questions are on the C)IHE exam and what score do I need?

The exam has 100 multiple-choice questions, runs approximately two hours, and requires a minimum of 70% to pass. The split between scored and unscored questions is not stated in the reviewed official material.

Do I have to buy the course to take the exam?

No. Course purchase is not required to buy the exam. Mile2 does suggest about 12 months of network-technology experience, networking and TCP/IP knowledge, and essential Linux knowledge before you sit.

Is the C)IHE exam weighted by domain?

No official weights have been published in the reviewed material. The twelve modules are unweighted preparation scope, so you cannot rely on a largest domain. Plan to cover all twelve areas.

How long does the certification last?

Under the current renewal policy it is valid for three years. Renewal calls for 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee, whose amount was not verified.

For a related overview, our pages on what the C)IHE certification is and the broader C)IHE certification hub explain how the pieces fit together.

Ready to pass your C)IHE exam?

Put this into practice with free C)IHE questions across every exam domain.