Certified Incident Handling Engineer Exam Prep
Free practice questions

Free C)IHE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)IHE exam has 100 questions and runs 2 hours.

These 10 free C)IHE questions are organized by exam domain, so you can see how each part of the Certified Incident Handling Engineer blueprint is tested. Reveal the answer and explanation under each question.

Domain 2: Incident Response Policy, Plan and Procedure Creation

Question 1

An organization is creating its incident response documentation. Which document should define the high-level authority, responsibilities, and expectations for incident handling?

Show answer & explanation

Correct answer: A - Incident response policy

Domain 3: Incident Response Team Structure

Question 2

A multinational company has regional security teams that handle local events while coordinating major incidents centrally. Which incident response team model characteristic is demonstrated?

Show answer & explanation

Correct answer: B - A model selected to match organizational requirements

Domain 4: Incident Response Team Services

Question 3

A response team publishes information about a newly discovered threat so other internal groups can prepare. Which incident response team service is being performed?

Show answer & explanation

Correct answer: A - Advisory distribution

Domain 6: Preparation

Question 4

A security team wants to identify malicious activity before a confirmed compromise occurs. Which preparation activity BEST supports this objective?

Show answer & explanation

Correct answer: A - Threat hunting based on hypotheses and available indicators

Domain 7: Detection and Analysis

Question 5

A security analyst observes repeated failed administrator logins followed by a successful login from an unfamiliar geographic location. Which action BEST represents the initial detection and analysis activity?

Show answer & explanation

Correct answer: B - Document the indicators and analyze whether the activity represents a security incident

Question 6

An investigator finds malware hash values, suspicious domains, and unusual outbound connections during an analysis. These findings are BEST classified as:

Show answer & explanation

Correct answer: C - Indicators of compromise

Domain 8: Containment, Eradication and Recovery

Question 7

During a ransomware investigation, a responder must limit damage while preserving the ability to investigate. Which consideration is MOST important when selecting a containment strategy?

Show answer & explanation

Correct answer: C - The balance between reducing impact and preserving investigative requirements

Question 8

After collecting a compromised workstation for forensic examination, which practice BEST protects the reliability of the evidence?

Show answer & explanation

Correct answer: B - Maintain proper evidence handling and documentation

Domain 9: Post Incident Activity

Question 9

Following a major incident, the response team meets to determine what worked, what failed, and what should change. The PRIMARY purpose of this activity is to:

Show answer & explanation

Correct answer: C - Capture lessons learned and improve future response

Domain 12: Coordination and Information Sharing

Question 10

A company joins a collaborative exercise where defenders and offensive testers work together to improve security visibility. This activity is known as:

Show answer & explanation

Correct answer: A - Purple teaming

The rest of the C)IHE blueprint

The C)IHE exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)IHE questions with explanations.

Continue in the free practice test →

View plans