EC-Council Certified Incident Handler (ECIH v2) Exam Guide
EC-Council’s Certified Incident Handler program validates knowledge used to prepare for, manage, contain, investigate, eradicate, and recover from security incidents. It is intended for candidates building practical incident-handling capability across malware, email, network, application, cloud, endpoint, and insider-threat situations. This guide helps you make two decisions: whether your current experience is a reasonable match for the certification, and how to turn the official ECIH v2 blueprint into a focused study plan without relying on leaked questions or unsupported exam claims.
What does ECIH v2 validate?
ECIH v2 is centered on the work of handling an incident from preparation and first response through containment, evidence gathering, eradication, forensic analysis, recovery, and follow-up. The program is designed to help learners prepare for, deal with, and eradicate threats and threat actors during incidents. That makes process discipline as important as technical knowledge.
The capability behind the credential
The official program description includes planning, recording, triage, notification, and containment activities. It also identifies post-incident containment, eradication, evidence gathering, forensic analysis, and recovery-related activities. In practice, prepare by learning how these activities connect rather than studying them as isolated vocabulary lists.
A useful mental model is a controlled sequence: establish readiness, recognize and validate an event, protect people and systems, preserve relevant evidence, limit spread, remove the cause, restore operations, and document what should change. The exact action depends on the incident type and organizational procedure, but the sequence helps you reason through scenario-based questions without treating every alert as the same problem. [https://www.eccouncil.org/train-certify/ec-council-certified-incident-handler-ecih-north-america/]
Who should consider it?
ECIH v2 is a sensible fit for a security analyst, SOC team member, incident responder, digital forensics learner, or security professional who needs a structured incident-handling framework. It can also suit someone moving toward response work, provided that person is prepared to study both operational process and technical incident categories.
Do not choose the certification solely because you recognize a few security tools or malware terms. The blueprint spans response decisions, first response, investigation themes, and several technology environments. If your background is mainly governance, networking, endpoint administration, or application security, use the domain list to identify the areas that need deliberate preparation rather than assuming experience in one area transfers automatically to all others.
The supplied official sources do not establish a universal prerequisite in the material provided here. Self-study candidates should verify eligibility before purchasing a voucher, because the EC-Council Store specifically instructs self-study students to apply for eligibility first. [https://store.eccouncil.org/product/ecih-ecc-exam-voucher/]
How is the ECIH v2 blueprint divided?
The ECIH v2 blueprint distributes coverage across a broad incident-handling workflow and incident types. Use the named domains to allocate study time and practice, but do not interpret a percentage as a promise about a particular question count or exam result. The official blueprint gives the following domain weights.
Process and first-response foundations
The Incident Response and Handling Process domain carries 11%, and First Response carries 11%. Together, these domains establish the operating logic for recognizing, organizing, documenting, and initially controlling an incident. Study them first because later technical domains are easier to apply when you understand the response sequence.
For the Incident Response and Handling Process domain, create a one-page workflow showing preparation, recording, triage, notification, containment, eradication, evidence handling, forensic analysis, recovery, and post-incident improvement. For First Response, focus on what must happen immediately, what should be preserved, who needs to be notified, and which actions could destroy evidence or worsen the incident. These are study recommendations based on the official program coverage, not additional EC-Council requirements. [https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf]
Malware, email, and network incidents
The Malware Incidents domain carries 11%, Email Security Incidents carries 12%, and Network Level Incidents carries 12%. These are substantial parts of the blueprint, so prepare to distinguish the type of evidence, affected assets, containment objective, and investigation priority associated with each category.
For malware study, connect indicators, execution behavior, persistence, scope, isolation, eradication, and recovery. For email incidents, organize notes around message artifacts, delivery, user interaction, malicious links or attachments, mailbox impact, and broader exposure. For network-level incidents, revise traffic evidence, affected hosts, communication paths, segmentation, and the difference between identifying suspicious activity and proving the incident’s scope.
Avoid studying these three domains as unrelated attack encyclopedias. Compare them only with their domain names attached: Malware Incidents 11%, Email Security Incidents 12%, and Network Level Incidents 12%. The comparison is useful for planning, but the blueprint percentages do not tell you which individual topics will appear in a particular exam attempt. [https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf]
Application, cloud, insider, and endpoint incidents
The Application Level Incidents domain carries 11%, Cloud Security Incidents carries 10%, Insider Threats carries 11%, and Endpoint Security Incidents carries 11%. These domains require you to adapt response reasoning to different sources of risk, evidence, ownership, and operational impact.
For Application Level Incidents, study the relationship between application behavior, logs, requests, authentication, input handling, affected components, and containment. For Cloud Security Incidents, map identity, service configuration, cloud resources, logs, access paths, and provider or customer responsibilities. For Insider Threats, include authorized access, unusual activity, data handling, employee context, privacy, escalation, and evidence preservation. For Endpoint Security Incidents, revise host isolation, local artifacts, user activity, persistence, remediation, and restoration.
The cloud domain is not a reason to ignore on-premises fundamentals, and the insider-threat domain is not simply a malware topic with a different attacker. Build a separate incident worksheet for each domain so you can state what changed, where evidence resides, who owns the affected control, and what containment could interrupt legitimate business activity. [https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf]
Which study order makes the domains easier to learn?
Study the response process before specializing in incident types, then use the technical domains to test whether you can apply that process under different conditions. A practical order is: process and first response; malware, email, and network; application, cloud, endpoint, and insider threats; finally, integrated review and weak-area repair.
Start with the two foundation domains rather than beginning with the most familiar technology. Write down the purpose of each stage, the decisions it enables, and the evidence or communication it requires. This prevents a common mistake: memorizing containment actions without understanding when validation, notification, documentation, or preservation should occur.
Next, work through Malware Incidents, Email Security Incidents, and Network Level Incidents. These categories give you varied practice with endpoint behavior, user-facing delivery, and network evidence. After each topic, answer four questions in your notes: What indicates an incident? What must be protected? What limits spread? What proves that remediation and recovery are complete?
Then study Application Level Incidents, Cloud Security Incidents, Insider Threats, and Endpoint Security Incidents as distinct contexts. Pay attention to differences in ownership and evidence location. A response decision that is reasonable for a compromised endpoint may be incomplete for a cloud identity or inappropriate when the suspected actor is an insider.
Finish with mixed revision rather than rereading one domain repeatedly. Select a scenario type at random, identify the applicable domain, place the event in the response lifecycle, and justify the next action. This method exposes whether you understand relationships between domains instead of merely recognizing isolated terms.
How should you use the official training resources?
The official ECIH training information describes hands-on learning through EC-Council iLabs and lists modules covering incident response, first response, malware, email, network, web application, cloud, and insider-threat incidents. Treat the labs as a place to connect concepts to actions, while using the blueprint as the authority for scope and weighting. [https://iclass.eccouncil.org/ecih-training/]
Turn each lab into a response record
Do not finish a lab by recording only whether a tool produced the expected output. Create a short incident record containing the alert or discovery point, affected asset, evidence examined, decision made, containment action, remaining uncertainty, and follow-up step. This mirrors the official program’s emphasis on recording, triage, notification, containment, evidence gathering, eradication, and recovery.
After completing an exercise, explain why the chosen action was appropriate and what information would change it. For example, ask whether isolation would preserve business continuity, whether collecting volatile evidence should precede shutdown, and whether the observed artifact establishes scope or merely suggests it. These are practical study questions, not claims about a particular live exam scenario.
Use a domain-to-evidence matrix
Create a table with one row for each official domain and columns for likely evidence, affected asset, immediate risk, containment concern, eradication concern, and recovery concern. Populate it from your training material and lab work. The table should remain concise enough to review quickly, but specific enough to distinguish an email artifact from a network artifact or a cloud identity event from an endpoint event.
If a row contains only definitions, it is not finished. Add a decision statement such as “preserve before modifying,” “confirm scope before broad containment,” or “escalate because authorized access may still represent harmful activity.” Keep these statements conditional; real response actions depend on evidence, policy, authority, and business impact.
What should a realistic preparation roadmap look like?
A useful roadmap has four passes: scope, learn, apply, and verify. The first pass maps the blueprint to your current knowledge; the second builds accurate notes; the third uses labs or controlled scenarios; the fourth tests retrieval and repairs weaknesses. Set your own calendar around available study time rather than adopting an unsupported fixed duration.
Pass one: establish scope
Obtain the current ECIH v2 blueprint and list every named domain in a tracking sheet. Mark each as strong, developing, or unfamiliar based on evidence such as work experience, completed training, or an explanation you can give without notes. Do not mark a domain strong merely because you have used a related product; incident handling asks what to do, why, and in what order.
Check the official training outline against your list. The training information includes incident response, first response, malware, email, network, web application, cloud, and insider-threat material, while the blueprint names Application Level Incidents and Endpoint Security Incidents among its domains. Resolve terminology differences in your notes instead of assuming that similar labels mean identical coverage. [https://iclass.eccouncil.org/our-courses/certified-incident-handler-ecih/]
Pass two: build working notes
For each domain, write a compact entry covering purpose, common indicators, evidence sources, first-response considerations, containment choices, eradication concerns, recovery checks, and documentation. Use your course material and official resources as the factual basis. The goal is not to create an enormous glossary; it is to make each domain usable in a response decision.
Keep process notes separate from technology notes. Process notes answer questions about triage, notification, authorization, recording, and lifecycle order. Technology notes answer questions about malware, email, network, applications, cloud, endpoints, and insider activity. Separating them makes it easier to see whether an error came from misunderstanding the workflow or misunderstanding the incident type.
Pass three: apply through practice
Use iLabs where available and supplement them with controlled, lawful exercises or written scenarios. For every exercise, produce a timeline and an evidence log. State what you know, what you infer, and what remains unknown. Then identify the least disruptive action that reduces risk while preserving the investigation, subject to the authority and procedures assumed by the exercise.
Practice communicating as well as investigating. Draft a short notification that identifies the incident, affected scope, current impact, action taken, uncertainty, and requested decision. This supports the program’s stated coverage of notification and recording and helps prevent technically correct but operationally incomplete answers. [https://www.eccouncil.org/train-certify/ec-council-certified-incident-handler-ecih-north-america/]
Pass four: verify readiness
Use closed-book retrieval: name the domain, outline the response sequence, identify evidence, and defend the next action. Review mistakes by cause, not just by topic. A missed question may reflect confusion between identification and containment, failure to preserve evidence, overbroad remediation, or a gap in cloud or endpoint knowledge.
Schedule the exam only after you can explain every blueprint domain and can move between lifecycle stages without relying on a memorized phrase. If one domain remains weak, return to the relevant training material and lab work. Do not use exam dumps or leaked questions as a substitute for competence; they do not establish that you understand incident-handling decisions and may expose you to inaccurate or unauthorized material.
What mistakes commonly waste preparation time?
The most damaging preparation mistakes are studying only familiar technologies, memorizing tool names without response logic, ignoring documentation and notification, and treating every incident as an endpoint problem. Correct these by returning to the blueprint, practicing lifecycle decisions, and requiring an evidence-based explanation for each proposed action.
Mistake: overinvesting in one familiar domain
A network analyst may spend most study time on Network Level Incidents, while an endpoint specialist may neglect cloud or application incidents. The blueprint does not support that narrow approach: Network Level Incidents carries 12%, while Application Level Incidents carries 11%, Cloud Security Incidents carries 10%, and Endpoint Security Incidents carries 11%. Build minimum working competence across all domains before deepening a specialty. [https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf]
Mistake: confusing detection with response
Recognizing a suspicious hash, message, connection, or login is not the same as handling the incident. For each indicator, ask what validates it, what establishes scope, what evidence must be preserved, who should be notified, and what action is authorized. This shifts study from recognition to controlled decision-making.
Avoid absolute rules such as always shutting down a host, always isolating an account immediately, or always collecting every artifact before taking action. A practical response balances safety, evidence preservation, business impact, authority, and the risk of continued compromise. Your notes should explain the conditions behind an action rather than presenting it as universal.
Mistake: treating the blueprint as a question list
The blueprint gives domain coverage and weights; it does not provide a list of live questions or guarantee the appearance of a particular scenario. Use it to prioritize study and audit coverage, not to search for memorized answers. A candidate who understands the underlying process can reason through unfamiliar wording more reliably than one who has memorized disconnected prompts.
Mistake: buying before confirming eligibility
The official store page states that self-study students must apply for eligibility before purchasing the exam voucher. Verify your route and eligibility through the official EC-Council process before paying. This is an administrative checkpoint, not a study task, but overlooking it can disrupt an otherwise ready exam plan. [https://store.eccouncil.org/product/ecih-ecc-exam-voucher/]
What delivery and voucher details are officially evidenced?
The supplied EC-Council Store listing describes the ECIH exam voucher as an online exam remotely proctored by the RPS team. It lists the voucher at $450.00, says it is non-transferable, and states that it is valid for a year from the date of release. Confirm the current product page and policies before purchase because commercial and administrative details can change. [https://store.eccouncil.org/product/ecih-ecc-exam-voucher/]
Plan the purchase separately from study readiness
The store listing says orders received on working days are processed within 48 hours and that weekend orders are processed the next working day. Use that information only as a processing expectation, not as a guaranteed appointment date. Before ordering, confirm eligibility, check the voucher terms, and make sure the release date and validity period fit your intended scheduling plan.
The supplied evidence does not establish the exam’s question count, duration, passing score, language options, or a full technical checklist for remote proctoring. Do not rely on third-party claims for those details. Review the current official candidate and scheduling instructions when you are ready to book.
Understand the retake route before you need it
The official store lists an ECIH retake voucher at $199.00. It is limited to candidates approved by EC-Council through the stated retake application process, is remotely proctored by RPS, is non-transferable, and is valid for a year from the date of release. Treat this as a policy-dependent option, not as part of the initial booking plan. [https://store.eccouncil.org/product/ecih-retake-exam-voucher/]
If a result does not go as planned, review the official retake requirements and policy before purchasing anything. Identify weak domains from your preparation records, rebuild understanding through the relevant training and labs, and then follow the approval process. A retake voucher does not replace diagnosis and targeted study.
How can you prepare for the remote exam appointment?
Because the supplied voucher evidence identifies online delivery with remote proctoring by RPS, treat appointment preparation as an administrative workstream. Confirm the current scheduling, identity, environment, and technical requirements from the official instructions before the appointment; the supplied research does not provide enough detail to specify those requirements safely.
Complete an evidence check
Before scheduling, confirm that your eligibility is approved if you are taking the self-study route, that the voucher belongs to you, and that its release date and validity period are understood. Keep the official order and scheduling information accessible. Do not assume that a voucher purchase alone completes every candidate or appointment step.
Use the official EC-Council pages for current instructions rather than relying on an old forum post or a provider’s generic remote-testing checklist. Delivery arrangements, technical requirements, and policies are operational details; they should be verified close to scheduling.
Protect the appointment from avoidable study errors
Do not spend the final preparation session learning an entirely new tool or chasing an unverified topic list. Review your lifecycle diagram, domain matrix, error log, and evidence-preservation principles. The final check should reveal uncertainty that can still be repaired, not create anxiety through endless content collection.
Keep exam conduct separate from exam content. Use only permitted materials and follow the proctor’s current instructions. This guide does not establish what resources may be present during the exam, so obtain that information from the official delivery instructions before the appointment.
What should you do during final review?
Final review should test decisions, not merely recognition. Select each blueprint domain, explain how an incident would be recognized and scoped, identify immediate priorities, and trace the case through containment, evidence handling, eradication, recovery, and documentation. Mark any step you cannot defend and use it to direct the last study session.
Use a one-page decision checklist
Your checklist can include these prompts: What is the suspected incident? What evidence supports it? What asset, identity, application, or service is affected? What is the immediate risk? What must be preserved? What notification or authorization is needed? What containment limits harm without creating unnecessary loss? How will eradication be confirmed? What recovery evidence and post-incident record are required?
Keep the checklist aligned with the official program’s documented focus on planning, recording, triage, notification, containment, eradication, evidence gathering, forensic analysis, and recovery-related activities. It is a revision aid, not an official exam checklist. [https://www.eccouncil.org/train-certify/ec-council-certified-incident-handler-ecih-north-america/]
Audit every domain once
Review the two 12% domains—Email Security Incidents and Network Level Incidents—alongside each 11% domain: Incident Response and Handling Process, First Response, Malware Incidents, Application Level Incidents, Insider Threats, and Endpoint Security Incidents. Then review Cloud Security Incidents at 10%. Keep every percentage attached to its official domain name, and use the review to find gaps rather than to predict exact exam content. [https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf]
Finish by explaining one integrated case in your own words. It should move from an initial signal through triage, notification, containment, evidence preservation, eradication, recovery, and documentation while accounting for the relevant technology domain. If your explanation jumps directly from detection to deletion, return to the process material before scheduling.
What is the next action after reading this guide?
Download or open the official ECIH v2 blueprint, create the nine-domain tracking sheet, and rate your current competence without consulting notes. Then choose the first study block around the weakest foundation—Incident Response and Handling Process or First Response—before moving into incident-specific labs and scenarios. Verify eligibility and current voucher information only when your study evidence supports scheduling.
Your immediate checklist is practical: map every blueprint domain; build a response lifecycle diagram; create the domain-to-evidence matrix; complete hands-on or controlled practice; maintain an error log; review all domains with their official weights; confirm self-study eligibility if relevant; and check current remote-proctoring and voucher instructions through EC-Council. This sequence gives preparation a measurable direction without pretending that a memorized question set can replace incident-handling ability.
Conclusion
ECIH v2 preparation is strongest when the blueprint becomes a decision framework rather than a list of labels. Learn the response lifecycle, apply it across malware, email, network, application, cloud, insider, and endpoint incidents, and use hands-on practice to expose weak reasoning. Before purchasing or scheduling, verify eligibility, voucher terms, and current remote-proctoring instructions from EC-Council. Then book only when you can justify the next response action with evidence, preservation, containment, and recovery in mind.
Related exams
- 312-39 exam — Certified SOC Analyst (CSA)
- 312-49v10 exam — Computer Hacking Forensic Investigator (CHFI-v10)
- 312-50v11 exam — Certified Ethical Hacker Exam (CEH v11)
- 312-85 exam — Certified Threat Intelligence Analyst (CTIA)
- 412-79v10 exam — EC-Council Certified Security Analyst (ECSA) V10
- CEH-v11 exam — Certified Ethical Hacker CEH v11