Study Guide

EC-Council Certified Incident Handler (ECIH) Study Guide

Prepare for the EC-Council ECIH exam with the v2 blueprint domains, the nine-stage IH&R process, verified exam facts, and a worked scenario.

Updated September 202611 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

The ECIH exam is a 3-hour, 100-question multiple-choice test delivered through the EC-Council Exam Portal; EC-Council sets the passing cut score per exam form, and published cut scores can range from 60% to 85%. The published ECIH Exam Blueprint v2 weights nine domains, from the incident response and handling process through endpoint security. The most efficient preparation is to master the nine IH&R stages once, then work through each blueprint domain, because the content re-applies that single process across incident categories.

What the ECIH credential covers

ECIH v3 teaches the complete incident handling and response process, from preparation through post-incident activities, applied to malware, email, network, web application, cloud, insider threat, and endpoint incidents.

EC-Council's Certified Incident Handler program — branded as version 3 on the program page — is built to equip you to prepare for, deal with, and eradicate threats during an incident. The course covers risk assessment methodologies and the laws and policies related to incident handling, alongside hands-on labs that teach the tactical procedures for planning, recording, triaging, notifying, and containing incidents.

The program also addresses post-incident work such as evidence gathering and forensic analysis, plus countermeasures aimed at preventing a repeat incident. EC-Council describes it as ANAB-accredited, approved by the US Department of Defense under directive 8140, aligned with the NICE 2.0 framework, and based on an industry-wide job task analysis.

For context, EC-Council frames incident response as the structured approach to handling security incidents, cyber threats, and data breaches, aiming to identify, contain, and minimize the cost of an attack. That framing is why the credential is process-centered rather than tool-centered.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; What is Incident Response | Become a Incident Handler | EC-Council — EC-Council explainer on incident response definitions and CSIRT roles

Exam format, eligibility, and training options

The exam has 100 multiple-choice questions, lasts 3 hours, and runs on the EC-Council Exam Portal (prefix 212-89 at the ECC Exam Center). EC-Council sets a cut score per exam form, and published cut scores can range from 60% to 85%.

The official program page lists the exam as 100 questions, 3 hours, multiple choice, delivered through the EC-Council Exam Portal. EC-Council's certification page adds the exam prefix 212-89 and availability at the ECC Exam Center, and explains that because exams are provided in multiple forms, cut scores are set on a per-form basis and can range from 60% to 85%. Treat any single percentage as form-specific rather than a universal pass mark.

EC-Council's candidate FAQ states that to qualify for the ECIH program you need at least 1 year of experience working as a cybersecurity professional, and the program is positioned for mid-level to senior-level practitioners. If your background is earlier-career, EC-Council's career-path materials route you through foundational and core certifications such as CCT, CND, and CEH before this specialization. Confirm current entry requirements when you enroll, since issuers can change policies.

Training is available three ways: iLearn as asynchronous self-study, iWeek as live online instructor-led training, or in person through an EC-Council Accredited Training Center. The course runs 3 days with 24 hours of class time, about half of it lab work. Exam vouchers are handled through your training center or instructor, and EC-Council's FAQ notes that official courseware is recommended but not mandatory for the exam.

  • Questions: 100, multiple choice
  • Duration: 3 hours
  • Availability: EC-Council Exam Portal (prefix 212-89, ECC Exam Center)
  • Passing: cut score set per exam form; published range 60% to 85%
  • Eligibility: EC-Council states at least 1 year of cybersecurity experience
  • Training: iLearn (self-study), iWeek (live online), or an Accredited Training Center

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; EC-Council Certified Incident Handler — https://cert.eccouncil.org/ec-council-certified-incident-handler.html; Cyber Incident Response Career Path | EC-Council — Career path and certification roadmap pages placing ECIH in the specialization tier; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

The nine-stage process is the study backbone

Learn the nine IH&R stages in order and understand what each one changes: preparation, incident recording and assignment, triage, notification, containment, evidence gathering and forensic analysis, eradication, recovery, and post-incident activities.

EC-Council presents the IH&R process as nine stages. Triage is where an event becomes a declared incident. Notification identifies who must know. Containment limits damage. Evidence gathering and forensic analysis support both understanding and possible prosecution. Eradication removes the root cause, recovery restores operations, and post-incident activities feed the next preparation cycle.

Reciting the list is step one; explaining why each stage sits where it does is the actual study goal. Write one sentence per stage for a generic incident, then notice where stages interact. Notification often overlaps containment because stakeholders must be told while systems are being isolated. Post-incident activities close the loop by updating policies and training, which is why preparation effectively begins the next incident.

Once you can trace those handoffs without notes, the framework becomes the lens for every incident-type module that follows. That is the point of the process-first approach: the course teaches one structure and applies it repeatedly, so your study should mirror that structure.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs

What the exam blueprint covers: nine domains and weights

The published ECIH Exam Blueprint v2 weights nine domains: incident response and handling process (11%), first response (11%), malware incidents (11%), email security incidents (12%), network level incidents (12%), application level incidents (11%), cloud security incidents (10%), insider threats (11%), and endpoint security incidents (11%).

Separate two version labels. The credential itself is branded v3 on EC-Council's program pages, while the published examination scope is the document titled ECIH Exam Blueprint v2. The blueprint, not the training module list, is the scope authority, so build your study plan from the nine domains and weights below.

Each blueprint domain maps onto the course modules you will study: the process domain covers the nine IH&R stages, frameworks, standards, and laws; first response covers securing the scene, collecting, and preserving evidence; and the seven incident domains apply the process to malware, email, network, web application, cloud, insider, and endpoint incidents, including mobile, IoT, and OT cases. Use the weights to allocate study time, and note that EC-Council updates exams over time, so check for a newer blueprint before you register.

Blueprint domainWeight (%)
1. Incident Response and Handling Process11
2. First Response11
3. Malware Incidents11
4. Email Security Incidents12
5. Network Level Incidents12
6. Application Level Incidents11
7. Cloud Security Incidents10
8. Insider Threats11
9. Endpoint Security Incidents11

Official sources used: ECIH Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf; ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

First response: what Module 03 expects

Module 03 covers four procedures: the concept of first response, securing and documenting the crime scene, collecting evidence at the scene, and preserving, packaging, and transporting evidence.

The official outline names the sub-topics directly, so treat them as your checklist. Securing the scene means controlling who touches what and documenting the state you found. Collection means recording how and when each item was acquired, by whom, and with which tools. Preservation, packaging, and transportation protect what you collected after acquisition.

Documentation quality at this point determines what every later stage can rely on, because evidence gathering and forensic analysis is a named stage in the IH&R process. When you study, rehearse the full journey of a seized item from the scene to a lab, naming each control along the way. If you cannot narrate that journey without gaps, reread the Module 03 objectives, because this is a compact, procedure-heavy body of content rather than a broad survey topic.

The official outline also lists first-response procedure among the program's key topics, covering evidence collection, documentation, preservation, packaging, and transportation. Make the order and purpose of these steps your study target; the outline does not name specific tools for this module.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; ECIH Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf

Practice: map a ransomware incident onto the nine stages

The exercise below is fully self-contained: the organizational response policy is stated in the prompt, so the only external knowledge you need is the published list of nine IH&R stages.

Use the exercise below as a paper self-check. Every premise you need is stated in the prompt; the answer follows from the nine-stage process EC-Council publishes plus the supplied policy, so if you disagree with the answer, identify which stage definition or premise you misread.

Practice exercise

Assumptions: your organization's approved IH&R policy directs handlers to record and assign the incident, triage it, and notify the incident response lead; after those steps, the policy requires isolating affected hosts from the network, then capturing a forensic image of each isolated host before any eradication or rebuild begins; recovery follows eradication. Scenario: a workstation begins encrypting files and is still connected to a shared drive. Using the nine-stage IH&R process EC-Council publishes, name the stage that covers (a) isolating the workstation, (b) capturing the forensic image, and (c) removing the malware and rebuilding the machine, and explain in one sentence why the policy requires imaging before the rebuild.

Show the worked answer

(a) Containment covers isolating the workstation so it can no longer reach the shared drive. (b) Evidence gathering and forensic analysis covers capturing the image. (c) Eradication covers removing the malware, and recovery covers rebuilding and restoring the machine. The policy requires imaging first because the image preserves what eradication and recovery will overwrite: without it, analysts may be unable to establish how the malware arrived or whether other systems were affected, so the root cause could survive the rebuild.

The four actions in this exercise map directly onto stages named in EC-Council's published process: containment, evidence gathering and forensic analysis, eradication, and recovery. The imaging-before-rebuild sequencing comes from the stated policy, not from a universal rule; organizations can and do order response steps differently, so on the exam read the policy or scenario premises given and apply the stage definitions to them.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs

Study priorities and a self-check list

Work through the blueprint domains in weight order, drill the nine stages until they are automatic, and finish with concrete self-checks rather than a feeling of readiness. EC-Council publishes no required study duration; pace the work yourself.

Start with the two heaviest domains, email security incidents and network level incidents, then the process and first response domains, since every incident category re-uses those stages. Cover the remaining categories, and use the case-study and best-practice objectives in the corresponding course modules to deepen each domain.

Before you finish, check yourself against concrete items rather than a feeling of readiness. Each check maps to a section of this guide, so a failure tells you where to return.

  • You can name all nine IH&R stages and explain the purpose of each.
  • Given a paper scenario with stated policy premises, you can name the stage each response action belongs to.
  • You can distinguish the Cyber Kill Chain from MITRE ATT&CK, and match each defensive fundamental, such as vulnerability assessment and threat hunting, to the question it answers.
  • You can describe the first-response sub-topics and the order in which they occur.
  • You have written a stage mapping for all seven incident categories and found at least one difference in each.

Official sources used: ECIH Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf; ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs

Career routes and related credentials

ECIH maps to incident response roles such as incident handler, CSIRT analyst, SOC analyst, and digital forensic analyst. EC-Council suggests CHFI for a digital forensics path, CSA and CND for blue-team work, and CCISO for executive progression.

The program page lists target roles including incident handler, incident response analyst or manager, CSIRT analyst, SOC analyst, cyber forensic investigator, and digital forensic analyst. Under the US Department of Defense directive 8140 framework, ECIH is approved for the Cyber Defense Incident Responder work role (531).

For progression, EC-Council positions CHFI as the route to a digital forensics and incident response (DFIR) specialization, CND and CSA as blue-team options, and CCISO for an executive path. The broader EC-Council career-path material places ECIH in the advance and specialization tier after foundational and core certifications.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; Cyber Incident Response Career Path | EC-Council — Career path and certification roadmap pages placing ECIH in the specialization tier

Final checklist and official documents

Confirm the exam logistics, verify your eligibility, study the nine blueprint domains and the nine IH&R stages, and check pricing directly with EC-Council, since the fee depends on delivery mode.

The verified facts in this guide come from EC-Council's official ECIH pages, the candidate FAQ, and the published ECIH Exam Blueprint v2. Two items remain open: the exact exam or certification fee, which EC-Council states varies by delivery mode and directs candidates to its advisors and training centers, and the specific cut score for your exam form, which is set per form within the published 60% to 85% range.

Your next steps are short: confirm eligibility with your experience record, choose a delivery mode, download the official brochure and the current exam blueprint, and begin with the nine-stage process. From there, work through the blueprint domains and the scenario exercise above until the stage definitions are automatic.

Official sources used: ECIH Certification | Cybersecurity Incident Response | EC-Council — Official ECIH program page, including course outline, training and exam details, eligibility, careers, and FAQs; ECIH Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf; EC-Council Certified Incident Handler — https://cert.eccouncil.org/ec-council-certified-incident-handler.html

Official sources used

Facts checked against EC-Council's official ECIH page:

Your next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Certified Incident Handler (ECIH).

Which version of the ECIH applies?
EC-Council brands the credential as ECIH v3, while the published examination scope document is titled ECIH Exam Blueprint v2. Treat the blueprint as the exam scope authority, and check EC-Council's site for a newer blueprint before registering, since the issuer updates exams over time.
How is ECIH different from the CHFI credential?
ECIH is an incident handling credential in which evidence gathering and forensic analysis is one stage of a broader response process. CHFI is EC-Council's dedicated digital forensics program, positioned as the route to a DFIR specialization. If you want the responder skill set, study ECIH; if you want deeper forensic methodology, CHFI is the related path EC-Council recommends.
Is ECIH suitable for beginners?
EC-Council states the course targets mid-level to senior-level cybersecurity professionals, with a minimum of one year of experience in the domain. Beginners are directed instead to foundational certifications such as the CCT and the essentials-level courses on the EC-Council career path.
What score do I need to pass, and what does the exam cost?
EC-Council does not publish a single fixed pass mark: exams are provided in multiple forms, and cut scores are set per form, ranging from 60% to 85%. Certification cost varies by delivery mode; EC-Council directs candidates to its advisors and training centers for pricing and vouchers.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.