- What C)IHE Actually Is
- Who Issues It and How the Exam Works
- Who the Certification Targets
- The Twelve Preparation Areas
- The NIST Model Behind the Outline
- Cyber Range and Class Values
- Pricing and Registration Mechanics
- Validity and Renewal
- Sequencing Your Preparation
- Where the Credential Fits Professionally
- Frequently Asked Questions
- C)IHE is Mile2's Certified Incident Handling Engineer credential, tested online through the Mile2 Learning Management System.
- The exam has 100 multiple-choice questions, runs approximately two hours, and requires a minimum score of 70%.
- Twelve unweighted course modules define the preparation scope; no official domain percentages have been published.
- Suggested background is 12 months of network-technology experience plus TCP/IP and essential Linux knowledge.
What C)IHE Actually Is
C)IHE stands for Certified Incident Handling Engineer. It is a certification from Mile2 that validates a candidate's grasp of how organizations prepare for, detect, contain, and learn from security incidents. The emphasis is on the full lifecycle of incident handling rather than on a single tool or a single attack technique. If you want a quick definition-level overview of the acronym, our short explainers on what C)IHE stands for and the meaning of C)IHE cover the basics.
A note on terminology: the same letters are used by other credentials in the industry. This article concerns only Mile2's Certified Incident Handling Engineer, and every fact below is drawn from that program's published course and renewal material. If you encounter exam fees, pass rates, or domain weightings for a similarly abbreviated credential, do not assume they apply here.
Who Issues It and How the Exam Works
Mile2 administers the examination online through its Learning Management System. The format, as stated in the current course outline, is straightforward:
| Attribute | C)IHE Detail |
|---|---|
| Issuer | Mile2 |
| Delivery | Online, via the Mile2 Learning Management System |
| Question count | 100 multiple-choice questions |
| Duration | Approximately 2 hours |
| Minimum passing score | 70% |
| Scored vs. unscored split | Not stated in reviewed material |
| Candidate pass rate | Not publicly disclosed in reviewed official material |
Several administrative details are simply not confirmed in the public documents we reviewed: whether the exam is open-book, whether a calculator is permitted, how remote proctoring is handled, and whether the test is adaptive. Rather than guess, check the conditions shown inside your Mile2 account before exam day. For deeper discussion of the scoring threshold, see our page on the C)IHE passing score, and for what is and is not known about outcomes, the C)IHE pass rate article explains why no figure can responsibly be quoted.
Who the Certification Targets
Mile2 suggests that candidates bring roughly 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions rather than hard gates. The reviewed material does not verify a mandatory degree requirement or a required number of professional references, and buying the exam does not require purchasing the course. Our C)IHE requirements guide walks through what that means in practice for different backgrounds.
In practical terms, the credential speaks to people who will sit inside or alongside a response function: security analysts, SOC staff, system and network administrators who get pulled into incidents, and team leads who must write the policies and plans that responders follow. Because so much of the material concerns policy, team structure, and information sharing, it also suits professionals moving from operations into formal incident-response roles.
The Twelve Preparation Areas
The current linked Mile2 outline contains a Module 00 course introduction plus twelve substantive modules. Module 00 is not counted as preparation content. The twelve substantive modules are best treated as unweighted preparation scope: Mile2 has not published percentages, so no domain can honestly be called the "largest." Any allocation of study time is editorial judgment, not an official blueprint. For a longer walkthrough of each area, see the complete guide to all 12 C)IHE content areas.
Foundations and Planning (Modules 1 through 5)
Domain 1: Incident Handling Explained
This opening module defines the vocabulary the rest of the exam assumes.
- What an incident is, and what incident handling is
- The difference between incident handling (IH) and incident response (IR)
- The incident response process and seven reasons to build a response plan
- How to build an effective team, considerations for creating one, and tips for team members
Domain 2: Incident Response Policy, Plan and Procedure Creation
Expect questions that separate three documents candidates often blur together.
- The incident response policy
- The incident response plan
- Incident response procedures
- Sharing information with outside parties
Domain 3: Incident Response Team Structure
This area is about organizational design rather than technical detection.
- Team models and how to select among them
- Incident response personnel
- Dependencies within organizations
Domain 4: Incident Response Team Services
What a response team offers beyond reacting to alerts.
- Intrusion detection
- Advisory distribution
- Education and awareness
- Information sharing
Domain 5: Incident Response Recommendations
Guidance on standing up and sustaining a capability.
- Establishing a formal incident response capability
- Establishing information sharing capabilities
- Building an incident response team
Operational Lifecycle (Modules 6 through 9)
Domain 6: Preparation
The issuer prints this one as "Chapter 06" inside the otherwise sequential list, but it is the sixth substantive item. It covers what you do before anything goes wrong.
- Threat hunting and threat analysis frameworks
- Tools and toolkits
- Policy and procedures
- Preventing incidents
Domain 7: Detection and Analysis
The diagnostic heart of the syllabus.
- Attack vectors and signs of an incident
- Sources of precursors and indicators
- Incident analysis, documentation, prioritization, and notification
Domain 8: Containment, Eradication and Recovery
Decision-making under pressure, tested through scenario-style reasoning.
- Selecting the right containment strategy
- Gathering and handling evidence
- Identifying the attacking hosts
- Eradication and recovery
Domain 9: Post Incident Activity
The closing loop that turns an incident into organizational improvement.
- Lessons learned
- Using collected incident data
- Evidence retention
Process Maturity and Collaboration (Modules 10 through 12)
Domain 10: Incident Handling Checklist
A short module on turning knowledge into repeatable artifacts: the purpose of checklists and how to build them.
Domain 11: Incident Handling Recommendations
Consolidated recommendations, including how to implement threat intelligence.
Domain 12: Coordination and Information Sharing
Often underestimated by technical candidates.
- Coordination and purple teaming
- Information sharing techniques, including granular information sharing
- Sharing recommendations
The NIST Model Behind the Outline
The current linked outline carries a version string of vs. 922021 and describes the older four-phase NIST 800-61 incident response model. NIST later published Revision 3 on April 3, 2025, but we could not verify that Mile2 has adopted it. That distinction matters for candidates: the four-phase model appearing in the course content is historical course material, not evidence that the certification now follows the revised guidance.
Cyber Range and Class Values
Mile2's training offering includes Cyber Range exercises, a five-day class, and 40 CEUs. It is easy to misread these. The Cyber Range supports training; it does not establish a practical component in the certification exam. Likewise, the five-day length and the 40 CEUs are course values, not the exam's duration, and certainly not scoring weights. The exam itself is the 100-question, roughly two-hour online test. For more on course-side options, see our overview of C)IHE training.
Pricing and Registration Mechanics
The official indexed offer is an Exam Combo that includes the exam, a simulator, and a guide, listed at USD $500 on sale against an original $795. What we could not verify: the price of the exam on its own, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Treat the combo figures as a snapshot and confirm current pricing at checkout. Course purchase is not required to buy the exam, which keeps a self-study route open. The C)IHE certification cost breakdown explains how to think through the total outlay, and scheduling questions are addressed in the C)IHE exam dates guide.
Validity and Renewal
Under Mile2's dedicated certification renewal policy, the credential is valid for three years. Renewal requires 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee (the amount is not verified here).
Sequencing Your Preparation
Because the twelve areas build on one another, order matters more than volume. One sensible way to sequence the work, tied to this specific syllabus rather than to generic advice:
Vocabulary and Documents
- Domains 1 and 2: lock in IH versus IR and the policy/plan/procedure distinction
- Domains 3 to 5: team models, services, and capability recommendations
The Lifecycle
- Domains 6 to 9: preparation, detection and analysis, containment/eradication/recovery, post-incident
- Practice prioritization and containment scenarios, since these reward judgment
Maturity and Sharing
- Domains 10 to 12: checklists, recommendations, threat intelligence, coordination
- Full timed run of 100 questions against the roughly two-hour limit
Front-loading the planning domains pays off because later material, such as evidence handling and information sharing, reuses their terminology. For a fuller method, read our C)IHE study guide, keep the C)IHE cheat sheet nearby for final review, and gauge your readiness with timed questions on the practice test site. If you are wondering about effort, how hard the C)IHE exam is offers context.
Key Takeaway
Since no domain weights are published, do not skip the "soft" modules. Team structure, policy creation, and information sharing make up a large share of the twelve areas, and a 70% threshold leaves little room to neglect them.
Where the Credential Fits Professionally
Incident handling skills are relevant to security operations centers, internal response teams, managed security providers, and IT departments that own their own recovery processes. We do not cite salary figures or hiring statistics here, because none are verified for this credential. If you are weighing the investment, our analyses of whether the C)IHE is worth it and C)IHE salary considerations discuss how to evaluate return without relying on invented numbers, and C)IHE jobs looks at the kinds of roles where this knowledge applies.
Frequently Asked Questions
It stands for Certified Incident Handling Engineer, a certification issued by Mile2. Other credentials share similar abbreviations, so always confirm you are reading about the Mile2 program.
The exam has 100 multiple-choice questions, takes approximately two hours, and requires a minimum score of 70%. The split between scored and unscored questions is not stated in the reviewed material.
No. The twelve modules in the current outline are unweighted preparation scope, not a verified weighted blueprint. Mile2 has not published percentages, so no single area can be called the largest.
No. Course purchase is not required to buy the exam. The indexed Exam Combo bundles the exam, a simulator, and a guide, but the combo's price and sale terms should be confirmed at checkout.
It is valid for three years. Renewal under the current dedicated policy requires 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee, whose amount is not verified here.