C)IHE logo
Focused certification exam prep
Start practice

What Is C)IHE?

TL;DR
  • C)IHE is Mile2's Certified Incident Handling Engineer credential, tested online through the Mile2 Learning Management System.
  • The exam has 100 multiple-choice questions, runs approximately two hours, and requires a minimum score of 70%.
  • Twelve unweighted course modules define the preparation scope; no official domain percentages have been published.
  • Suggested background is 12 months of network-technology experience plus TCP/IP and essential Linux knowledge.

What C)IHE Actually Is

C)IHE stands for Certified Incident Handling Engineer. It is a certification from Mile2 that validates a candidate's grasp of how organizations prepare for, detect, contain, and learn from security incidents. The emphasis is on the full lifecycle of incident handling rather than on a single tool or a single attack technique. If you want a quick definition-level overview of the acronym, our short explainers on what C)IHE stands for and the meaning of C)IHE cover the basics.

A note on terminology: the same letters are used by other credentials in the industry. This article concerns only Mile2's Certified Incident Handling Engineer, and every fact below is drawn from that program's published course and renewal material. If you encounter exam fees, pass rates, or domain weightings for a similarly abbreviated credential, do not assume they apply here.

Who Issues It and How the Exam Works

Mile2 administers the examination online through its Learning Management System. The format, as stated in the current course outline, is straightforward:

AttributeC)IHE Detail
IssuerMile2
DeliveryOnline, via the Mile2 Learning Management System
Question count100 multiple-choice questions
DurationApproximately 2 hours
Minimum passing score70%
Scored vs. unscored splitNot stated in reviewed material
Candidate pass rateNot publicly disclosed in reviewed official material

Several administrative details are simply not confirmed in the public documents we reviewed: whether the exam is open-book, whether a calculator is permitted, how remote proctoring is handled, and whether the test is adaptive. Rather than guess, check the conditions shown inside your Mile2 account before exam day. For deeper discussion of the scoring threshold, see our page on the C)IHE passing score, and for what is and is not known about outcomes, the C)IHE pass rate article explains why no figure can responsibly be quoted.

Format reality check: The exam is multiple-choice only. The outline does not describe any hands-on or practical component in the certification test itself. Preparation should therefore center on recognizing correct processes, definitions, and decision logic across the twelve course areas rather than on performing live tool exercises.

Who the Certification Targets

Mile2 suggests that candidates bring roughly 12 months of network-technology experience, working knowledge of networking and TCP/IP, and essential Linux knowledge. These are suggestions rather than hard gates. The reviewed material does not verify a mandatory degree requirement or a required number of professional references, and buying the exam does not require purchasing the course. Our C)IHE requirements guide walks through what that means in practice for different backgrounds.

In practical terms, the credential speaks to people who will sit inside or alongside a response function: security analysts, SOC staff, system and network administrators who get pulled into incidents, and team leads who must write the policies and plans that responders follow. Because so much of the material concerns policy, team structure, and information sharing, it also suits professionals moving from operations into formal incident-response roles.

The Twelve Preparation Areas

The current linked Mile2 outline contains a Module 00 course introduction plus twelve substantive modules. Module 00 is not counted as preparation content. The twelve substantive modules are best treated as unweighted preparation scope: Mile2 has not published percentages, so no domain can honestly be called the "largest." Any allocation of study time is editorial judgment, not an official blueprint. For a longer walkthrough of each area, see the complete guide to all 12 C)IHE content areas.

Foundations and Planning (Modules 1 through 5)

Domain 1: Incident Handling Explained

This opening module defines the vocabulary the rest of the exam assumes.

  • What an incident is, and what incident handling is
  • The difference between incident handling (IH) and incident response (IR)
  • The incident response process and seven reasons to build a response plan
  • How to build an effective team, considerations for creating one, and tips for team members

Domain 2: Incident Response Policy, Plan and Procedure Creation

Expect questions that separate three documents candidates often blur together.

  • The incident response policy
  • The incident response plan
  • Incident response procedures
  • Sharing information with outside parties

Domain 3: Incident Response Team Structure

This area is about organizational design rather than technical detection.

  • Team models and how to select among them
  • Incident response personnel
  • Dependencies within organizations

Domain 4: Incident Response Team Services

What a response team offers beyond reacting to alerts.

  • Intrusion detection
  • Advisory distribution
  • Education and awareness
  • Information sharing

Domain 5: Incident Response Recommendations

Guidance on standing up and sustaining a capability.

  • Establishing a formal incident response capability
  • Establishing information sharing capabilities
  • Building an incident response team

Operational Lifecycle (Modules 6 through 9)

Domain 6: Preparation

The issuer prints this one as "Chapter 06" inside the otherwise sequential list, but it is the sixth substantive item. It covers what you do before anything goes wrong.

  • Threat hunting and threat analysis frameworks
  • Tools and toolkits
  • Policy and procedures
  • Preventing incidents

Domain 7: Detection and Analysis

The diagnostic heart of the syllabus.

  • Attack vectors and signs of an incident
  • Sources of precursors and indicators
  • Incident analysis, documentation, prioritization, and notification

Domain 8: Containment, Eradication and Recovery

Decision-making under pressure, tested through scenario-style reasoning.

  • Selecting the right containment strategy
  • Gathering and handling evidence
  • Identifying the attacking hosts
  • Eradication and recovery

Domain 9: Post Incident Activity

The closing loop that turns an incident into organizational improvement.

  • Lessons learned
  • Using collected incident data
  • Evidence retention

Process Maturity and Collaboration (Modules 10 through 12)

Domain 10: Incident Handling Checklist

A short module on turning knowledge into repeatable artifacts: the purpose of checklists and how to build them.

Domain 11: Incident Handling Recommendations

Consolidated recommendations, including how to implement threat intelligence.

Domain 12: Coordination and Information Sharing

Often underestimated by technical candidates.

  • Coordination and purple teaming
  • Information sharing techniques, including granular information sharing
  • Sharing recommendations

The NIST Model Behind the Outline

The current linked outline carries a version string of vs. 922021 and describes the older four-phase NIST 800-61 incident response model. NIST later published Revision 3 on April 3, 2025, but we could not verify that Mile2 has adopted it. That distinction matters for candidates: the four-phase model appearing in the course content is historical course material, not evidence that the certification now follows the revised guidance.

Practical consequence: Study the lifecycle as the Mile2 outline presents it, with its preparation, detection and analysis, containment/eradication/recovery, and post-incident phases. Reading Revision 3 can enrich your professional understanding, but do not assume exam questions reflect it unless Mile2 says so.

Cyber Range and Class Values

Mile2's training offering includes Cyber Range exercises, a five-day class, and 40 CEUs. It is easy to misread these. The Cyber Range supports training; it does not establish a practical component in the certification exam. Likewise, the five-day length and the 40 CEUs are course values, not the exam's duration, and certainly not scoring weights. The exam itself is the 100-question, roughly two-hour online test. For more on course-side options, see our overview of C)IHE training.

Pricing and Registration Mechanics

The official indexed offer is an Exam Combo that includes the exam, a simulator, and a guide, listed at USD $500 on sale against an original $795. What we could not verify: the price of the exam on its own, any member versus nonmember distinction, checkout taxes, and how long the sale lasts. Treat the combo figures as a snapshot and confirm current pricing at checkout. Course purchase is not required to buy the exam, which keeps a self-study route open. The C)IHE certification cost breakdown explains how to think through the total outlay, and scheduling questions are addressed in the C)IHE exam dates guide.

Validity and Renewal

Under Mile2's dedicated certification renewal policy, the credential is valid for three years. Renewal requires 60 qualifying CEUs, agreement to Mile2's policies and ethics, and payment of the applicable renewal fee (the amount is not verified here).

Watch for outdated wording: Older course PDFs mention retaking the current exam and earning 20 CEUs per year. For current administration, rely on the dedicated renewal policy rather than combining both sets of requirements. And remember that CEUs are a maintenance mechanism, never an exam weight.

Sequencing Your Preparation

Because the twelve areas build on one another, order matters more than volume. One sensible way to sequence the work, tied to this specific syllabus rather than to generic advice:

Weeks 1-2

Vocabulary and Documents

  • Domains 1 and 2: lock in IH versus IR and the policy/plan/procedure distinction
  • Domains 3 to 5: team models, services, and capability recommendations
Weeks 3-4

The Lifecycle

  • Domains 6 to 9: preparation, detection and analysis, containment/eradication/recovery, post-incident
  • Practice prioritization and containment scenarios, since these reward judgment
Week 5

Maturity and Sharing

  • Domains 10 to 12: checklists, recommendations, threat intelligence, coordination
  • Full timed run of 100 questions against the roughly two-hour limit

Front-loading the planning domains pays off because later material, such as evidence handling and information sharing, reuses their terminology. For a fuller method, read our C)IHE study guide, keep the C)IHE cheat sheet nearby for final review, and gauge your readiness with timed questions on the practice test site. If you are wondering about effort, how hard the C)IHE exam is offers context.

Key Takeaway

Since no domain weights are published, do not skip the "soft" modules. Team structure, policy creation, and information sharing make up a large share of the twelve areas, and a 70% threshold leaves little room to neglect them.

Where the Credential Fits Professionally

Incident handling skills are relevant to security operations centers, internal response teams, managed security providers, and IT departments that own their own recovery processes. We do not cite salary figures or hiring statistics here, because none are verified for this credential. If you are weighing the investment, our analyses of whether the C)IHE is worth it and C)IHE salary considerations discuss how to evaluate return without relying on invented numbers, and C)IHE jobs looks at the kinds of roles where this knowledge applies.

Frequently Asked Questions

What does C)IHE stand for?

It stands for Certified Incident Handling Engineer, a certification issued by Mile2. Other credentials share similar abbreviations, so always confirm you are reading about the Mile2 program.

How many questions are on the exam, and what score passes?

The exam has 100 multiple-choice questions, takes approximately two hours, and requires a minimum score of 70%. The split between scored and unscored questions is not stated in the reviewed material.

Are there official domain weightings?

No. The twelve modules in the current outline are unweighted preparation scope, not a verified weighted blueprint. Mile2 has not published percentages, so no single area can be called the largest.

Do I have to buy the course to take the exam?

No. Course purchase is not required to buy the exam. The indexed Exam Combo bundles the exam, a simulator, and a guide, but the combo's price and sale terms should be confirmed at checkout.

How long does the certification last, and how is it renewed?

It is valid for three years. Renewal under the current dedicated policy requires 60 qualifying CEUs, agreement to policies and ethics, and payment of the applicable renewal fee, whose amount is not verified here.

Ready to pass your C)IHE exam?

Put this into practice with free C)IHE questions across every exam domain.