EC-Council Certified Incident Handler (ECIH v2) Exam Guide
The ECIH v2 exam is intended to assess incident-handling knowledge across response processes, first response, malware, email, network, application, cloud, insider-threat, and endpoint-security incidents. The program is designed to help learners prepare for, deal with, and eradicate threats and threat actors during incidents. This guide helps you decide whether your current skills are ready, which blueprint domains deserve study time, how to use hands-on practice, and what to confirm before scheduling the exam.
What does the ECIH certification focus on?
ECIH focuses on the practical sequence of managing a security incident: planning and recording the event, triaging it, notifying the appropriate parties, containing the threat, gathering evidence, supporting forensic analysis, eradicating the cause, and contributing to recovery. The exam blueprint organizes that work across a general response process and incident types affecting different technologies and users.
EC-Council describes the Certified Incident Handler program as preparing learners to deal with and eradicate threats and threat actors during incidents. That wording is important for preparation: this is not simply a terminology review. You should be able to connect an observed incident to a defensible response decision, explain what should happen next, and distinguish containment, eradication, evidence gathering, and recovery-related activities.
The official program description also identifies malware, email-security, network-security, web-application, cloud-security, and insider-threat incidents. Endpoint Security Incidents appears as a separate domain in the v2 blueprint. Study therefore needs both a repeatable response method and technology-specific judgment. A candidate who knows individual tools but cannot place their use in an incident workflow has a significant preparation gap.
EC-Council describes the program as ANAB-accredited and approved under U.S. DoD 8140. Those are program-level descriptions from EC-Council, not a substitute for checking the current eligibility, purchasing, or certification information before making a scheduling decision. Source: https://www.eccouncil.org/train-certify/ec-council-certified-incident-handler-ecih-north-america/
Who should consider ECIH v2?
ECIH is most relevant to a learner whose intended work includes investigating, coordinating, containing, or documenting security incidents. It can also provide a structured target for a security practitioner who understands basic defensive operations but needs a clearer incident-response framework. The official material establishes the program’s incident-handling purpose; it does not, in the supplied evidence, define a complete job-role list or universal prerequisite.
Use your current responsibilities rather than a job title to judge fit. Ask whether you already encounter alerts, suspicious files, compromised accounts, abnormal network activity, application incidents, cloud events, or insider-threat concerns. Then ask whether you can explain the first response, triage, notification, containment, evidence, eradication, and recovery implications of those events. If several answers are no, begin with fundamentals before setting an exam date.
Self-study candidates should pay particular attention to the official purchasing condition: the EC-Council Store says self-study students must apply for eligibility before purchasing the exam voucher. That is an administrative requirement stated on the voucher page, not a recommendation. Confirm the application process and any current criteria through EC-Council before paying for an attempt. Source: https://store.eccouncil.org/product/ecih-ecc-exam-voucher/
A useful readiness test
Create a short incident worksheet without consulting notes. For a hypothetical alert, record the facts you would preserve, the questions that shape triage, the people or functions that may need notification, the immediate containment choice, and the evidence or recovery concerns. Repeat the exercise for a malware event, an email-security event, a network event, and an application event. The worksheet exposes reasoning gaps more effectively than rereading definitions.
Which ECIH v2 domains are measured?
The v2 blueprint distributes the exam across nine named domains. Use the percentages to allocate attention, but do not treat them as a reason to ignore a smaller domain: the blueprint covers the full incident-handling scope, and a weak foundation can affect performance across several domains. The official blueprint is the controlling reference for the current domain wording and weights.
The Incident Response and Handling Process domain accounts for 11%. First Response accounts for 11%. Malware Incidents accounts for 11%. Email Security Incidents accounts for 12%, and Network Level Incidents accounts for 12%. Application Level Incidents accounts for 11%. Cloud Security Incidents accounts for 10%. Insider Threats accounts for 11%, and Endpoint Security Incidents accounts for 11%.
The weights create a practical planning signal. Email Security Incidents and Network Level Incidents are the two 12% domains identified in the supplied blueprint. Cloud Security Incidents is the 10% domain. Each of the remaining named domains carries 11%. Do not compare these figures without their domain labels: the number only has meaning when attached to the domain the blueprint names.
Download and read the ECIH Exam Blueprint v2 before finalizing your study plan. Check the domain names and any task-level detail there rather than relying on a summary. Source: https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf
How should the weights change your schedule?
Start with the response process and first response because they provide a decision structure for the incident-specific domains. Then give deliberate practice to Email Security Incidents and Network Level Incidents, the two domains assigned 12% each. Keep Malware Incidents, Application Level Incidents, Insider Threats, and Endpoint Security Incidents in the core rotation, and reserve focused review for Cloud Security Incidents, which the blueprint assigns 10%.
The percentages should not become a crude hour-for-hour formula. If your professional background is heavily network-oriented, Network Level Incidents may need less introductory reading but more scenario testing. A learner with little cloud exposure should not under-study Cloud Security Incidents merely because that domain is assigned 10%. Use the blueprint weight and your diagnostic results together.
What skills should you study first?
Study the response lifecycle as a set of decisions, records, and handoffs rather than as an isolated list of phases. You need a working mental model for planning, recording, triage, notification, containment, post-incident containment, eradication, evidence gathering, forensic analysis, and recovery-related work. Once that model is stable, attach the distinct indicators and response concerns of each incident type.
A useful first pass asks five questions for every topic: What event or evidence suggests an incident? What must be preserved before it changes? How should the event be triaged? What action limits damage without destroying useful evidence? What must be documented or communicated afterward? These questions are study prompts, not claims about a particular live exam scenario.
For First Response, practice the order and purpose of immediate actions. Avoid jumping straight to eradication because an apparently quick fix can remove information needed to understand scope and cause. For Malware Incidents, connect identification, safe handling, containment, evidence, eradication, and recovery considerations. For Email Security Incidents, study the relationship between message evidence, affected identities, delivery scope, and user or organizational impact.
For Network Level Incidents and Endpoint Security Incidents, separate network observations from host observations. A network symptom can indicate several causes, while an endpoint artifact may help establish execution, persistence, or impact. For Application Level Incidents, think about the application boundary, affected data or functions, and how application evidence supports triage. For Cloud Security Incidents, include the cloud-specific location of logs, identities, resources, and administrative control.
For Insider Threats, avoid reducing the topic to suspicion. Study how an incident handler would preserve facts, limit unnecessary exposure, coordinate notification, and support a controlled investigation. The supplied official program description confirms coverage of insider-threat incidents; detailed operational procedures should come from the blueprint and authorized training material rather than assumptions added to this guide. Source: https://www.eccouncil.org/train-certify/ec-council-certified-incident-handler-ecih-north-america/
Turn each domain into an output
For every blueprint domain, produce something you can inspect: a one-page decision map, a glossary linked to actions, a sample incident record, or a short explanation of evidence and containment choices. Outputs reveal whether you can use the knowledge. A page of copied definitions does not show whether you can select the next defensible response step.
How can hands-on practice improve preparation?
Hands-on work is most useful when it makes you observe, record, interpret, and decide. EC-Council says the ECIH training program includes hands-on learning through EC-Council iLabs and modules covering incident response, first response, malware, email, network, web application, cloud, and insider-threat incidents. If you use the official training, treat the labs as opportunities to connect artifacts to the response process rather than as demonstrations to watch passively.
Before a lab, write down the question you are trying to answer. During the exercise, capture the evidence you used, the conclusion you reached, the action you would take, and what remains uncertain. Afterward, reconstruct the incident record from memory and compare it with your notes. This builds the habits of recording and explaining decisions that the program emphasizes.
Do not make lab completion your only measure of readiness. A learner may follow a guided sequence successfully while still struggling with an unfamiliar scenario. After each exercise, change one condition: alter the suspected entry point, broaden the affected scope, introduce a notification constraint, or require evidence preservation before containment. The point is not to simulate real exam questions; it is to test whether your reasoning transfers.
If you do not have access to the official labs, use a controlled learning environment and authorized sample data. Do not investigate real organizations, access systems without permission, or use leaked exam material. Dumps, unauthorized question collections, and memorization of purported answers do not demonstrate incident-handling competence and cannot guarantee a pass.
The official training page is the source for the iLabs and module coverage described above: https://iclass.eccouncil.org/ecih-training/
A repeatable lab debrief
End each exercise with four entries: observed facts, working assessment, immediate response decision, and follow-up evidence or recovery work. Add one sentence explaining why you rejected the most tempting alternative. This debrief takes less time than repeating an entire lab and gives you a growing library of reasoning patterns without pretending that a practice scenario is an actual exam item.
What study sequence works for ECIH v2?
A staged plan is more reliable than studying domains in random order. Build the common response process first, test immediate-response reasoning next, rotate through the incident-specific domains, and finish with mixed scenarios and blueprint-led review. The sequence below is a practical recommendation, not an EC-Council-mandated timetable; adjust it to your baseline knowledge and available study time.
Stage one: read the v2 blueprint and create a domain checklist. Mark each domain as unfamiliar, familiar but untested, or usable under a scenario. Do not begin by collecting large quantities of third-party notes. Your first task is to identify what the official blueprint expects you to cover and what evidence you have for your own readiness.
Stage two: study Incident Response and Handling Process together with First Response. Build a single flow that includes planning, recording, triage, notification, containment, evidence, eradication, and recovery-related work. Then apply it to a simple incident narrative. If you cannot explain why an action belongs at a particular point in the process, return to the concept before adding more incident types.
Stage three: work through Malware Incidents, Email Security Incidents, Network Level Incidents, Application Level Incidents, Cloud Security Incidents, Insider Threats, and Endpoint Security Incidents. For each domain, make a compact comparison between detection clues, affected assets or identities, evidence concerns, containment options, and post-incident tasks. The comparison is your own study tool; it is not a substitute for the official domain detail.
Stage four: mix domains. A single event can involve email, endpoints, network activity, cloud resources, or an application at the same time. Practice deciding which facts are known, which are assumptions, what should happen immediately, and which specialist or stakeholder may need involvement. Mixed practice prevents you from answering every problem as if it belonged only to the chapter you studied most recently.
Stage five: conduct a readiness review using the blueprint. Explain every domain aloud or in writing without opening your notes. Revisit only the weak areas revealed by that review. Schedule administrative tasks separately from study tasks so that an eligibility question, voucher condition, or proctoring requirement does not become a last-minute surprise.
A practical four-part weekly cycle
Use one study cycle for learning, one for retrieval, one for application, and one for correction. During learning, read the official material. During retrieval, close it and reproduce the process or domain map. During application, solve an authorized scenario or complete a lab. During correction, record the exact distinction you missed and test it again later. This cycle is more informative than repeatedly highlighting the same pages.
If your time is limited
Do not omit entire domains. Begin with the blueprint, learn the common response process, then prioritize the domains where your diagnostic work shows both weakness and high decision complexity. Give explicit attention to Email Security Incidents and Network Level Incidents because each is assigned 12% in the official blueprint, while retaining review coverage for all other named domains.
How do you know when you are ready to schedule?
Schedule only after you can use the blueprint to explain both your strengths and your remaining risks. Readiness is not a feeling produced by finishing a course; it is the ability to retrieve the response process, distinguish incident types, justify immediate actions, and document what evidence or follow-up work matters. Use a final self-review to decide whether more study or administrative preparation is appropriate.
Take a blank sheet and write the nine blueprint domains. Under each, add the central response questions, the evidence concerns, and the containment or follow-up decisions you would expect to make. Then review a set of mixed, authorized practice scenarios without looking up every term immediately. Mark uncertainty separately from an incorrect answer: both need attention, but they require different remedies.
A strong final review explains why an option is appropriate, not merely why other options sound unfamiliar. When two actions appear plausible, compare their effect on evidence, scope, safety, notification, and recovery. If your notes contain only vocabulary and no decision rationale, postpone scheduling and add scenario-based practice.
Use the official assessment page and the current blueprint for final confirmation of what EC-Council publishes about the assessment. The supplied assessment-page evidence does not provide enough verified detail here to state a question count, duration, passing score, language list, or other exam-format specifics, so this guide does not invent them. Sources: https://www.eccouncil.org/train-certify/ecih-assessment/ and https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf
What delivery and voucher details should you confirm?
The EC-Council Store lists the ECIH Exam Voucher – RPS at $450.00. The product page states that delivery is online and the exam is remotely proctored by the RPS team. It also says the voucher is non-transferable and valid for a year from the date of release. Treat these as current store terms to verify at purchase, not as permanent conditions detached from the official page.
Self-study students must apply for eligibility before purchasing the voucher, according to the same store listing. The page also states that orders received on the store’s working days are processed within 48 hours, while orders received on weekends are processed the next working day. Because processing and eligibility affect scheduling, check the live store listing and application information before selecting an exam date.
If a retake becomes necessary, the EC-Council Store lists the ECIH Retake Exam Voucher – RPS at $199.00. The listing says it is limited to candidates approved by EC-Council through the retake application process, is remotely proctored by RPS, is non-transferable, and is valid for a year from the date of release. A retake voucher is therefore not an automatic fallback to purchase in advance.
Confirm the current retake policy and approval process through the official links identified by EC-Council. Do not schedule around an assumed retake entitlement, and do not treat a listed price or validity period as protection against changes to store terms. Sources: https://store.eccouncil.org/product/ecih-ecc-exam-voucher/ and https://store.eccouncil.org/product/ecih-retake-exam-voucher/
A sensible scheduling checklist
Before purchasing, verify whether you need eligibility approval, which delivery option the voucher identifies, how remote-proctoring requirements will be met, the voucher release and validity terms, and the applicable retake rules. Keep the confirmation and policy links with your study plan. If any detail is unclear, ask EC-Council or the listed provider rather than relying on a training-site summary.
Which preparation mistakes cost candidates time?
The most avoidable mistake is studying incident names without learning the response decisions that connect them. Other common errors include ignoring the blueprint, treating every alert as confirmed compromise, skipping evidence considerations, and purchasing before checking self-study eligibility. Correct these by making every study session produce a decision map, an incident record, or a written explanation of competing actions.
Mistake one is giving equal attention to every page while ignoring the blueprint. The remedy is not to abandon lower-weight domains; it is to use the official percentages and your diagnostic results to set priorities. Keep the domain label attached to every planning note so that you do not accidentally turn a percentage into an unsupported comparison.
Mistake two is confusing first response with the entire incident lifecycle. Immediate actions matter, but the official program description also includes planning, recording, triage, notification, containment, evidence gathering, forensic analysis, eradication, and recovery-related activities. Build study questions that move beyond the first action and ask what must be documented and revisited later.
Mistake three is treating containment and eradication as interchangeable. In your notes, define the purpose of each action in the scenario you are studying, then identify what evidence or scope information could be lost if you act too quickly. This is a preparation technique, not a claim about one prescribed response for every incident.
Mistake four is relying on memorized answers, dumps, or leaked material. Such material is unauthorized, may be inaccurate, and does not build the ability to interpret a new incident. Use the blueprint, official training, iLabs where available, and authorized practice instead. No study source can guarantee a passing result.
Mistake five is assuming that a familiar technology equals incident-response readiness. A network administrator, application specialist, cloud operator, or endpoint analyst may know one environment deeply while still needing practice with notification, evidence, containment, and recovery decisions. Use cross-domain scenarios to expose that imbalance.
Mistake six is postponing administrative checks. The official voucher page says self-study students must apply for eligibility before purchasing. Check that condition before budgeting for the voucher or choosing a target date. Administrative readiness and technical readiness are separate workstreams; complete both.
How should you use official material without overfitting?
Use the blueprint to define scope, the program description to understand the intended capability, the training page to identify the stated module and lab coverage, and the store page to verify purchase conditions. Each source has a different job. Treating a store listing as a technical syllabus or a marketing description as a complete exam specification creates avoidable uncertainty.
Keep a source-controlled notes page. For each claim you write down, record whether it came from the blueprint, the program description, the training page, or the voucher listing. Separate official requirements from your own recommendations with labels such as “official” and “study tactic.” This prevents a suggested sequence from being mistaken for a mandatory EC-Council rule.
The supplied evidence does not verify an exam duration, question count, passing score, language availability, prerequisites beyond the stated self-study eligibility instruction, or a current retirement date. Do not fill those gaps with figures from another certification or an outdated page. Before scheduling, consult EC-Council’s current assessment, eligibility, and voucher information directly.
This approach also protects your study plan from stale assumptions. The v2 blueprint is the appropriate reference for the domain weights supplied here. If the official blueprint or store page changes, update the plan and scheduling decision instead of preserving an older summary because it is convenient.
What should you do in the final review period?
Use the final review to sharpen retrieval and decision quality, not to begin an entirely new library of material. Revisit the blueprint, complete mixed incident exercises, explain your choices in writing, and correct only the weaknesses your checks reveal. Finish the administrative checklist early enough to resolve eligibility or delivery questions through official channels.
First, reproduce the response process from memory and attach planning, recording, triage, notification, containment, evidence, forensic analysis, eradication, and recovery-related considerations to it. Second, review every named blueprint domain, giving deliberate attention to Email Security Incidents and Network Level Incidents at 12% each and Cloud Security Incidents at 10%, while retaining the other domains at their official labels and weights.
Third, perform a cross-domain exercise. Begin with one observable event and identify how the interpretation could involve an email message, endpoint, network, application, cloud resource, malware, or insider-threat concern. The aim is to practice separating facts from assumptions and selecting the next defensible action, not to predict or reproduce live exam content.
Fourth, prepare a last-error sheet. Record terms you confuse, response steps you reverse, evidence you forget to preserve, and notification or containment assumptions that require qualification. Review that sheet through retrieval rather than passive reading. If the same weakness persists, extend preparation instead of treating the calendar as proof of readiness.
Finally, verify the current voucher conditions, eligibility status if applicable, remote-proctoring arrangements, voucher validity, and retake-policy information. Use the official pages, not an unofficial listing. Sources: https://cert.eccouncil.org/wp-content/uploads/2024/01/ECIH-Exam-Blueprint-v2.pdf, https://store.eccouncil.org/product/ecih-ecc-exam-voucher/, and https://www.eccouncil.org/train-certify/ecih-assessment/
What are the next actions for an ECIH v2 candidate?
Begin with the official v2 blueprint, assess every domain honestly, and choose study activities that make you explain and document incident decisions. Then verify eligibility and voucher conditions before purchasing. This produces a defensible preparation decision: continue building capability, or move to scheduling after both technical and administrative checks are complete.
Download the blueprint and create the nine-domain checklist. Mark your current confidence and evidence for each mark. Do not use confidence alone; require an output such as a process map, domain summary, lab debrief, or scenario explanation.
Study the Incident Response and Handling Process and First Response domains first. Build the common workflow before specializing. Follow with the incident-specific domains, using the official percentages to maintain priority while allowing extra time for topics where your experience is limited.
Use iLabs if they are part of your selected official training route, and debrief each exercise through facts, assessment, action, and follow-up. If you use other practice material, confirm that it is authorized and aligned with the blueprint. Reject dumps and purported leaked questions.
Run a mixed-domain readiness review. Explain not only what you would do, but why, what evidence or scope information matters, and what later work remains. Recheck every weak area and update your last-error sheet.
Before buying or scheduling, read the current EC-Council assessment, eligibility, voucher, and retake information. Confirm the conditions that apply to your route, especially the self-study eligibility instruction and the remote-proctored RPS delivery listed on the voucher page.
The goal is not to memorize a set of answers. It is to demonstrate disciplined incident handling across the blueprint’s domains and to make a scheduling decision based on verified requirements and observed preparation gaps.
Conclusion
ECIH v2 preparation should combine a blueprint-led study plan with repeated incident-response reasoning. Learn the common process, apply it across malware, email, network, application, cloud, insider-threat, and endpoint situations, and use hands-on work to improve evidence-based decisions. Keep official requirements separate from study recommendations, verify current voucher and eligibility terms, and schedule only when your own mixed-domain review shows that you can explain and document the response—not merely recognize terminology.
Related exams
- 312-39 exam — Certified SOC Analyst (CSA)
- 312-49v10 exam — Computer Hacking Forensic Investigator (CHFI-v10)
- 312-50v11 exam — Certified Ethical Hacker Exam (CEH v11)
- 312-85 exam — Certified Threat Intelligence Analyst (CTIA)
- 412-79v10 exam — EC-Council Certified Security Analyst (ECSA) V10
- CEH-v11 exam — Certified Ethical Hacker CEH v11